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Foreword 



This Technical Specification has been produced by the 3' Generation Partnership Project (3GPP). 

The contents of the present document are subject to continuing work within the TSG and may change following formal 
TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an 
identifying change of release date and an increase in version number as follows: 

Version x.y.z 

where: 

X the first digit: 

1 presented to TSG for information; 

2 presented to TSG for approval; 

3 or greater indicates TSG approved document under change control. 

y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, 
updates, etc. 

z the third digit is incremented when editorial only changes have been incorporated in the document. 



Introduction 



The present document includes references to features which are not part of the Phase 2+ Release 96 of the GSM 
Technical specifications. All subclauses which were changed as a result of these features contain a marker (see table 
below) relevant to the particular feature. 

The following table lists all features that were introduced after GSM Release 96. 



Feature 


Designator 


BA Range IE handling 


$(impr-BA-range-handling)$ 


Advanced Speech Call Item 


$(ASCI)$ 


Call Completion Busy Subscriber 


$(CCBS)$ 


Mobile Assisted Frequency Allocation 


$(MAFA)$ 


Network Indication of Alerting in MS 


$(NIA)$ 
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Scope 



rd 



The present document specifies the procedures used at the radio interface core network protocols within the 3 
generation mobile telecommunications system and the digital cellular telecommunications system. 

It specifies the procedures used at the radio interface (Reference Point Um or Uu, see 3GPP TS 24.002 [15] or 
3GPP TS 23.002 [127]) for Call Control (CC), Mobility Management (MM), and Session Management (SM). 

When the notations for "further study" or "FS" or "FFS" are present in this TS they mean that the indicated text is not a 
normative portion of the present document. 

These procedures are defined in terms of messages exchanged over the control channels of the radio interface. The 
control channels are described in 3GPP TS 44.003 [16] and 3GPP TS 25.301 [128]. 

The structured functions and procedures of this protocol and the relationship with other layers and entities are described 
in general terms in 3GPP TS 24.007 [20]. 

1.1 Scope of the Technical Specification 

The procedures currently described in this TS are for the call control of circuit-switched connections, session 
management for GPRS services, mobility management and radio resource management for circuit-switched and GPRS 
services. 

3GPP TS 24.010 [21] contains functional procedures for support of supplementary services. 

3GPP TS 24.01 1 [22] contains functional procedures for support of point-to-point short message services. 

3GPP TS 24.012 [23] contains functional description of short message - cell broadcast. 

3GPP TS 44.060 [76] contains procedures for radio link control and medium access control (RLC/MAC) of packet data 
physical channels. 

3GPP TS 44.071 [23a] contains functional descriptions and procedures for support of location services. 

NOTE: "layer 3" includes the functions and protocols described in the present document. The terms "data link 
layer" and "layer 2" are used interchangeably to refer to the layer immediately below layer 3. 

1 .2 Application to the interface structures 

The procedures defined in the present document apply to the interface structures defined in 3GPP TS 44.003 [16] and 
3GPP TS 25.301 [128]. They use the functions and services provided by lower layers defined in 3GPP TS 44.005 [18] 
and 3GPP TS 44.006 [19] or 3GPP TS 25.331 [23c], 3GPP TS 25.322 [19b] and 3GPP TS 25.321 [19a]. 
3GPP TS 24.007 [20] gives the general description of layer 3 (A/Gb mode) and Non Access Stratum (lu mode and S 1 
mode) including procedures, messages format and error handling. 

1 .3 Structure of layer 3 procedures 

A building block method is used to describe the layer 3 procedures. 

The basic building blocks are "elementary procedures" provided by the protocol control entities of the three sublayers, 
i.e. radio resource management, mobility management and connection management sublayer. 

Complete layer 3 transactions consist of specific sequences of elementary procedures. The term "structured procedure" 
is used for these sequences. 
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1.4 Test procedures 



Test procedures of the GSM radio interface signalling are described in 3GPP TS 51.010 [39] and 
3GPPTS 5 1.02x series. 

1 .5 Use of logical channels in A/Gb mode 

The logical control channels are defined in 3GPP TS 45.002 [32]. In the following those control channels are 
considered which carry signalling information or specific types of user packet information: 

i) Broadcast Control CHannel (BCCH): downlink only, used to broadcast Cell specific information; 

ii) Synchronization CHannel (SCH): downlink only, used to broadcast synchronization and ESS identification 
information; 

iii) Paging CHannel (PCH): downlink only, used to send page requests to Mobile Stations (MSs); 

iv) Random Access CHannel (RACH): uplink only, used to request a Dedicated Control CHannel; 

v) Access Grant CHannel (AGCH): downlink only, used to allocate a Dedicated Control CHannel; 

vi) Standalone Dedicated Control CHannel (SDCCH): bi-directional; 

vii)Fast Associated Control CHannel (FACCH): bi-directional, associated with a Traffic CHannel; 

viii) Slow Associated Control CHannel (SACCH): bi-directional, associated with a SDCCH or a Traffic CHannel; 

ix) Cell Broadcast CHannel (CBCH): downlink only used for general (not point to point) short message information; 

x) Notification CHannel (NCH): downlink only, used to notify mobile stations of VBS (Voice Broadcast Service) 
calls or VGCS (Voice Group Call Service) calls. 

Two service access points are defined on signalling layer 2 which are discriminated by their Service Access Point 
Identifiers (SAPI) (see 3GPP TS 44.006 [19]): 

i) SAPI 0: supports the transfer of signalling information including user-user information; 

ii) SAPI 3: supports the transfer of user short messages. 

Layer 3 selects the service access point, the logical control channel and the mode of operation of layer 2 
(acknowledged, unacknowledged or random access, see 3GPP TS 44.005 [18] and 3GPP TS 44.006 [19]) as required 
for each individual message. 

1 .6 Overview of control procedures 
1 .6.1 List of procedures 

The following procedures are specified in the present document: 

a) Clause 4 specifies elementary procedures for Mobility Management: 
mobility management common procedures (subclause 4.3): 
TMSI reallocation procedure (subclause 4.3.1); 
authentication procedure (subclause 4.3.2); 
identification procedure (subclause 4.3.3); 
IMSI detach procedure (subclause 4.3.4); 
- abort procedure (subclause 4.3.5); 
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- MM information procedure (subclause 4.3.6). 
mobility management specific procedures (subclause 4.4): 

location updating procedure (subclause 4.4.1); 

- periodic updating (subclause 4.4.2); 
IMSI attach procedure (subclause 4.4.3); 

generic location updating procedure (subclause 4.4). 
connection management sublayer service provision: 

- mobility management connection establishment (subclause 4.5. 1); 

mobility management connection information transfer phase (subclause 4.5.2); 

- mobility management connection release (subclause 4.5.3). 
GPRS specific mobility management procedures (subclause 4.7): 

GPRS attach procedure (subclause 4.7.3); 

GPRS detach procedure (subclause 4.7.4); 

GPRS routing area updating procedure (subclause 4.7.5). 

GPRS common mobility management procedures (subclause 4.7): 

GPRS P-TMSI reallocation procedure (subclause 4.7.6); 

GPRS authentication and ciphering procedure (subclause 4.7.7); 

GPRS identification procedure (subclause 4.7.8); 

GPRS information procedure (subclause 4.7.12). 

b) Clause 5 specifies elementary procedures for circuit switched Call Control comprising the following elementary 
procedures: 

mobile originating call establishment (subclause 5.2.1); 

mobile terminating call establishment (subclause 5.2.2); 

signalling procedures during the active state (subclause 5.3): 

user notification procedure (subclause 5.3.1); 

call rearrangements (subclause 5.3.2); 

DTMF protocol control procedure (subclause 5.5.7); 

in-call modification (subclause 5.3.4). 
call clearing initiated by the mobile station (subclause 5.4.3); 
call clearing initiated by the network (subclause 5.4.4); 
miscellaneous procedures: 

in-band tones and announcements (subclause 5.5.1); 

status enquiry procedure (subclause 5.5.3); 

call re-establishment procedure (subclause 5.5.4). 
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d) Clause 6 specifies elementary procedures for session management: 
GPRS session management procedures (subclause 6.1): 

PDP context activation (subclauses 6.1.3.1 and 6.1.3.2); 
- PDP context modification (subclause 6.1.3.3); 

PDP context deactivation (subclause 6.1.3.4). 

MBMS context activation (subclause 6.1.3.8); 

MBMS context deactivation (subclause 6.1.3.9). 

The elementary procedures can be combined to form structured procedures. Examples of such structured procedures are 
given in clause 7. This part of the present document is only provided for guidance to assist implementations. 

Clause 8 specifies actions to be taken on various error conditions and also provides rules to ensure compatibility with 
future enhancements of the protocol. 

1 .7 Applicability of implementations 

The applicability of procedures of the present document for the mobile station is dependent on the services and 
functions which are to be supported by a mobile station. 

1 .7.1 Voice Group Call Service (VGCS) and Voice Broadcast Service 
(VBS) 

Voice Group Call Service and Voice Broadcast Service are applicable in A/Gb mode only. 

For mobile stations supporting the Voice Group Call Service or the Voice Broadcast Service, it is explicitly mentioned 
throughout the present document if a certain procedure is applicable only for such a service and, if necessary, how 
mobile stations not supporting such a service shall behave. 

For VGCS and VBS, the following possible mobile station implementations exist: 

support of listening to voice broadcast calls (VBS listening); 

support of originating a voice broadcast call (VBS originating); 

support of listening to voice group calls (VGCS listening); 

support of talking in voice group calls (VGCS talking. This always includes the implementation for VGCS 
listening); 

support of originating a voice group call (VGCS originating. This always includes the implementation for VGCS 
talking). 

Apart from the explicitly mentioned combinations, all possible combinations are optional and supported by the present 
document. 

The related terms are used in the present document, if information on these implementation options is required. 

1 .7.2 General Packet Radio Service (GPRS) 
1 .7.2.1 Packet services in GSIVI (A/Gb mode only) 

For mobile stations supporting the General Packet Radio Service (GPRS), it is explicitly mentioned throughout the 
technical specification if a certain procedure is applicable only for such a service and, if necessary, how mobile stations 
not supporting such a service shall behave. 
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A GPRS MS may operate in one of the following MS operation modes, see 3GPP TS 23.060 [74]: 

MS operation mode A; 

MS operation mode B; or 

MS operation mode C. 

The MS operation mode depends on the services that the MS is attached to, i.e., only GPRS or both GPRS and non- 
GPRS services, and upon the MS's capabilities to operate GPRS and other GSM services simultaneously. Mobile 
stations that are capable to operate GPRS services are referred to as GPRS MSs. 

NOTE: Other GSM technical specifications may refer to the MS operation modes A, B, and C as GPRS class-A 
MS, GPRS class-B MS, and GPRS class-C MS. 

It should be noted that it is possible that for a GPRS MS, the GMM procedures currently described in the ETS do not 
support combinations of VGCS, VBS and GPRS. The possible interactions are not studied yet. 

1 .7.2.2 Packet services in lu mode (lu mode only) 

An MS attached to packet switched domain may operate in one of the following MS operation modes, see 
3GPPTS 23.060 [74]: 

PS/CS mode of operation; or 

PS mode of operation. 

The terms 'PS/CS mode of operation' and 'PS mode of operation' are not used in the present document with some 
exceptions. Instead the terms 'MS operation mode A' and 'MS operation mode C are used. 

In network operation mode I and II (see 3GPP TS 23.060 [74]), an MS in PS/CS mode of operation shall use the same 
procedures as for a GPRS MS operating in MS operation mode A, unless it is explicitly stated for A/Gb mode only or 
lu mode only. 

In network operation mode I and II, an MS in PS mode of operation shall use the same procedures as for a GPRS MS 
operating in MS operation mode C, unless it is explicitly stated for A/Gb mode only or lu mode only. 

NOTE: Network operation mode III is not applicable for lu mode, see 3GPP TS 23.060 [74]. 

1 .8 Handling of NAS signalling low priority indication 

An MS configured for NAS signalling low priority indicates this by including the Device properties IE in the 
appropriate NAS message and setting the low priority indicator to "MS is configured to NAS signalling low priority" 
except for the following cases in which the MS shall set the low priority indicator to "MS is not configured for NAS 
signalling low priority": 

the MS is performing an attach for emergency bearer services; 

the MS has a PDN connection for emergency bearer services established and is performing mobility 
management procedures, or is establishing a PDN connection for emergency bearer services; 

the MS is accessing the network with access class 11-15; or 

- the MS is responding to paging. 

The network may use the NAS signalling low priority indication for NAS level mobility management congestion 
control on a per core network node basis and APN based congestion control. 

If the NAS signalling low priority indication is provided in an ACTIVATE PDP CONTEXT REQUEST message, the 
SGSN stores the NAS signalling low priority indication within the default PDP context activated due to this request. 
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2.1 Definitions and abbreviations 

For the purposes of the present document, the abbreviations defined in 3GPP TR 21.905 [2a] and the followings apply: 

CAT Customized Alerting Tone 

IP-CAN IP-Connectivity Access Network 

HNB Home Node B 

Kc 64-bit GSM ciphering key 

Kci28 128-bit GSM ciphering key 

L-GW Local PDN Gateway 
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LIPA Local IP Access 

TMGI Temporary Mobile Group Identity 

MTU Maximum Transfer Unit 

2.1.1 Random values 

In a number of places in the present document, it is mentioned that some value must take a "random" value, in a given 
range, or more generally with some statistical distribution. Such cases interest only the Mobile Station. 

It is required that there is a low probability that two MSs in the same conditions (including the case of two MSs of the 
same type from the same manufacturer) will choose the same value. Moreover, it is required that, if it happens that two 
MSs in similar conditions choose the same value, the probability of their choices being identical at the next occasion is 
the same as if their first choices had been different. 

The meaning of such a specification is that any statistical test for these values, done on a series of similar events, will 
obtain a result statistically compatible with the specified distribution. This shall hold even in the cases where the tests 
are conducted with a subset of possible events, with some common parameters. Moreover, basic tests of independence 
of the values within the series shall pass. 

Data against which correlation with the values shall not be found are the protocol state, or the IMSI, or identities or 
other unrelated information broadcast by the network, or the current TDMA frame number. 

2.1.2 Vocabulary 

For the purposes of the present document, the following terms and definitions apply: 

A GSM security context is established and stored in the MS and the network as a result of a successful 
execution of a GSM authentication challenge. The GSM security context for the CS domain consists of the GSM 
ciphering key and the ciphering key sequence number. The GSM security context for the PS domain consists of 
the GPRS GSM ciphering key and the GPRS ciphering key sequence number. 

A UMTS security context is established and stored in the MS and the network as a result of a successful 
execution of a UMTS authentication challenge. The UMTS security context for the CS domain consists of the 
UMTS ciphering key, the UMTS integrity key, the GSM ciphering key, the ciphering key sequence number and 
the GSM Kci28 (if an A5 ciphering algorithm that requires a 128-bit ciphering key is in use). The UMTS security 
context for the PS domain consists of the GPRS UMTS ciphering key, the GPRS UMTS integrity key, the GPRS 
GSM ciphering key, the GPRS ciphering key sequence number and the GPRS GSM Kc^s (if a GEA ciphering 
algorithm that requires a 128-bit ciphering key is in use). 

An MS is attached for emergency bearer services if it has successfully completed an attach for emergency 
bearer services or if it has only a PDN connection for emergency bearer services established. 

idle mode: In this mode, the mobile station is not allocated any dedicated channel; it listens to the CCCH and the 
BCCH; 

group receive mode: (only applicable for mobile stations supporting VGCS listening or VBS listening) In this 
mode, the mobile station is not allocated a dedicated channel with the network; it listens to the downlink of a 
voice broadcast channel or voice group call channel allocated to the cell. Occasionally, the mobile station has to 
Hsten to the BCCH of the serving cell as defined in 3GPP TS 43.022 [82] and 3GPP TS 45.008 [34]; 

dedicated mode: In this mode, the mobile station is allocated at least two dedicated channels, only one of them 
being a SACCH; 

- EAB: Extended Access Barring, see 3GPP TS 22.01 1 [138]. 

group transmit mode: (only applicable for mobile stations supporting VGCS talking) In this mode, one mobile 
station of a voice group call is allocated two dedicated channels, one of them being a SACCH. These channels 
can be allocated to one mobile station at a time but to different mobile stations during the voice group call; 

packet idle mode: (only applicable for mobile stations supporting GPRS) In this mode, mobile station is not 
allocated any radio resource on a packet data physical channel; it listens to the PBCCH and PCCCH or, if those 
are not provided by the network, to the BCCH and the CCCH, see 3GPP TS 44.060 [76]. 
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packet transfer mode: (only applicable for mobile stations supporting GPRS) In this mode, the mobile station is 
allocated radio resource on one or more packet data physical channels for the transfer of LLC PDUs. 

main DCCH: In Dedicated mode and group transmit mode, only two channels are used as DCCH, one being a 
SACCH, the other being a SDCCH or a FACCH; the SDCCH or FACCH is called here "the main DCCH"; 

A channel is activated if it can be used for transmission, in particular for signalling, at least with UI frames. On 
the SACCH, whenever activated, it must be ensured that a contiguous stream of layer 2 frames is sent; 

A TCH is connected if circuit mode user data can be transferred. A TCH cannot be connected if it is not 
activated. A TCH which is activated but not connected is used only for signalling, i.e. as a DCCH; 

The data link of SAPI on the main DCCH is called the main signalling link. Any message specified to be sent 
on the main signalling link is sent in acknowledged mode except when otherwise specified; 

- The term "to establish" a link is a short form for "to establish the multiframe mode" on that data link. It is 
possible to send UI frames on a data link even if it is not established as soon as the corresponding channel is 
activated. Except when otherwise indicated, a data link layer establishment is done without an information field. 

"channel set" is used to identify TCHs that carry related user information flows, e.g., in a multislot 
configuration used to support circuit switched connection(s), which therefore need to be handled together. 

A temporary block flow (TBF) is a physical connection used by the two RR peer entities to support the uni- 
directional transfer of LLC PDUs on packet data physical channels, see 3GPP TS 44.060 [76]. 

- RLC/MAC block: A RLC/MAC block is the protocol data unit exchanged between RLC/MAC entities, see 
3GPPTS 44.060 [76]. 

A GMM context is established when a GPRS attach procedure is successfully completed. 

- Network operation mode 

The three different network operation modes I, II, and III are defined in 3GPP TS 23.060 [74]. 

The network operation mode shall be indicated as system information. For proper operation, the network 
operation mode should be the same in each cell of one routing area. 

- GAN mode: See 3GPP TS 43.318 [75a]. 

- GPRS MS operation mode 

The three different GPRS MS operation modes A, B, and C are defined in 3GPP TS 23.060 [74]. 

RR connection: A RR connection is a dedicated physical circuit switched domain connection used by the two 
RR or RRC peer entities to support the upper layers' exchange of information flows. 

PS signalling connection is a peer to peer lu mode connection between MS and CN packet domain node. 

Inter-System change is a change of an MS from A/Gb mode to lu mode of operation or vice versa, or from S 1 
mode to A/Gb mode or lu mode of operation. 

GPRS: Packet Services for systems which operate the Gb or lu-PS interfaces. 

- GSM ciphering key: A 64-bit CS GSM ciphering key 

- GSM Kci28: A 128-bit CS GSM ciphering key 

- GPRS GSM ciphering key: A 64-bit PS GSM ciphering key 

- GPRS GSM Kci28: A 128-bit PS GSM ciphering key 

The label (A/Gb mode only) indicates this section or paragraph applies only to a system which operates in A/Gb 
mode, i.e. with a functional division that is in accordance with the use of an A or a Gb interface between the 
radio access network and the core network. For multi system case this is determined by the current serving radio 
access network. 
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The label (lu mode only) indicates this section or paragraph applies only to a system which operates in lu mode. 
The lu mode includes UTRAN and GERAN lu modes, i.e. with a functional division that is in accordance with 
the use of an lu-CS or lu-PS interface between the radio access network and the core network. For multi system 
case this is determined by the current serving radio access network. 

In A/Gb mode,... Indicates this paragraph applies only to a system which operates in A/Gb mode. For multi 
system case this is determined by the current serving radio access network. 

In lu mode,... Indicates this paragraph applies only to a system which operates in lu mode. The lu mode 
includes both UTRAN lu mode and GERAN lu mode. For multi system case this is determined by the current 
serving radio access network. 

In A/Gb mode and GERAN lu mode,... Indicates this paragraph applies only to a system which operates in 
A/Gb mode or GERAN lu mode. For multi system case this is determined by the current serving radio access 
network. 

In UTRAN lu mode,... Indicates this paragraph applies only to a system which operates in UTRAN lu mode. 
For multi system case this is determined by the current serving radio access network. 

In a shared network,... Indicates this paragraph applies only to a shared network. For the definition of shared 
network see 3GPP TS 23.122 [14]. 

NOTE: According to this definition, a multi-operator core network (MOCN) with common GERAN is not 
considered a shared network in 3GPP TS 23.122 [14] and in the present specification. 

- Multi-Operator Core Network (MOCN) with common GERAN: a network in which different core network 
operators are connected to a shared GERAN broadcasting only a single, common PLMN identity. 

A default PDF context is a PDP context activated by the PDP context activation procedure that establishes a 
PDN connection. The default PDP context remains active during the lifetime of the PDN connection. 

A PDP context for emergency bearer services is a default PDP context which was activated with request type 
"emergency", or any secondary PDP contexts associated to this default PDP context. 

Non-emergency PDP context: any PDP context which is not a PDP context for emergency bearer services. 

- SIM, Subscriber Identity Module (see 3GPP TS 42.017 [7]). 

- USIM, Universal Subscriber Identity Module (see 3GPP TS 21.111 [101]). 

MS, Mobile Station. The present document makes no distinction between MS and UE. 

Cell Notification is an (optimised) variant of the Cell Update Procedure which uses the LLC NULL frame for 
cell change notification which does not trigger the restart of the READY timer 

- DTM: dual transfer mode, see 3GPP TS 44.018 [84] and 3GPP TS 43.055 [87] 

The term "eCall only" applies to a mobile station which is in the eCall only mode, as described in 
3GPPTS 22.101 [8]. 

"removal of eCall only restriction" means that all the limitations as described in 3GPP TS 22.101 [8] for the 
eCall only mode do not apply any more. 

- Access domain selection: The process to select whether the CS domain or the IMS/IP-CAN is used to transmit 
the call control signalling between MS and core network. Definition derived from 3GPP TS 23.221 [131]. 

NAS level mobility management congestion control: Congestion control mechanism in the network in 
mobility management. "NAS level mobility management congestion control" consists of "subscribed APN based 
congestion control" and "general NAS level mobility management congestion control". 

- General NAS level mobility management congestion control: The type of congestion control that is apphed at 
a general overload or congestion situation in the network, e.g. lack of processing resources. 

Subscribed APN based congestion control: Congestion control in mobility management where the network 
can reject attach requests from MSs with a certain APN in the subscription. 
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- Mapped P-TMSI: a P-TMSI which is mapped from a GUTI previously allocated to the MS by an MME. 
Mapping rules are defined in 3GPP TS 23.003 [10]. Definition derived from 3GPP TS 23.401 [122]. 

- Native P-TMSI: a P-TMSI previously allocated by an SGSN. Definition derived from 3GPP TS 23.401 [122]. 

- Valid LAI: a LAI that is not deleted LAI. 

- EMM Combined UE Waiting Flag: See 3GPP TS 29.018 [141]. 

For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.401 [122], 
subclause 3.2, apply: 

Globally Unique MME Identifier (GUMMEI) 

Globally Unique Temporary Identity (GUTI) 

Idle Mode Signalling Reduction (ISR) 

M-Temporary Mobile Subscriber Identity (M-TMSI) 

PDN connection 

Tracking Area Identity (TAI) 

Temporary Identity used in Next update (TIN) 

For the purposes of the present document, the following terms and definitions given in 3GPP TS 24.301 [120] apply: 

CSG cell 

CSGID 

CSG selection 

LIPA PDN connection 

PDN connection for emergency bearer services 

SI mode 

For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.272 [133] apply: 

CS fallback 
SMS over SGs 

For the purposes of the present document, the following terms and definitions given in 3GPP TS 33.401 [123] apply: 

Current EPS security context 

Mapped security context 

eKSI 

CK' and IK' 

NAS downlink COUNT 

NAS uplink COUNT 

For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.251 [109] apply: 

Common PLMN 

Network Sharing non-supporting MS: see non-supporting UE. 

Network Sharing supporting MS: see supporting UE. 

For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.122 [14] apply: 

Suitable Cell 



3 Radio Resource management procedures 

See 3GPPTS 44.018 [84]. 
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4 Elementary procedures for Mobility Management 

4.1 General 

This clause describes the procedures used for mobility management for non-GPRS services and for GPRS-services at 
the radio interface (Reference Point Um and Uu). 

The main function of the Mobility Management sublayer is to support the mobility of user terminals, such as informing 
the network of its present location and providing user identity confidentiality. 

A further function of the MM sublayer is to provide connection management services to the different entities of the 
upper Connection Management (CM) sublayer (see 3GPP TS 24.007 [20]). 

There are two sets of procedures defined in this chapter: 

MM procedures for non-GPRS services (performed by the MM entity of the MM sublayer); and 

GMM procedures for GPRS services (performed by the GMM entity of the MM sublayer), see 
3GPPTS 24.007 [20]. 

All the MM procedures described in this clause can only be performed if a RR connection has been established between 
the MS and the network. Else, the MM sublayer has to initiate the establishment of a RR connection (see 
3GPP TS 44.018 [84] subclause 3.3 and 3GPP TS 25.331 [23c]). 

In A/Gb mode, the GMM procedures described in this clause, use services provided by the RR sublayer without prior 
RR connection establishment. 

In lu mode: all the GMM procedures described in this clause can only be performed if a PS signalling connection has 
been established between the MS and the network. Else, the GMM sublayer has to initiate the establishment of a PS 
signalling connection (see 3GPP TS 25.331 [23c]). 

GMM procedures are mandatory and applicable only for GPRS MSs and networks supporting those MSs. For GPRS 
MSs which are IMSI attached for both GPRS and non-GPRS services, some MM procedures are replaced by GMM 
combined procedures provided that the network operates in network operation mode I, i.e. is supporting combined 
GMM procedures. GMM combined procedures are not applicable for the GPRS MS operation mode C but are 
mandatory for the GPRS MS operation modes A and B and networks supporting network operation mode I, see 
3GPPTS 23.060 [74]. 

4.1 .1 MM and GMM procedures 

4.1 .1 .1 Types of MM and GMM procedures 

Depending on how they can be initiated, three types of MM procedures can be distinguished: 

1) MM common procedures: 

A MM common procedure can always be initiated whilst a RR connection exists. The procedures belonging to 
this type are: 

Initiated by the network: 

TMSI reallocation procedure; 

- authentication procedure; 
identification procedure; 

- MM information procedure; 

- abort procedure. 
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However, abort procedure is used only if an MM connection is being established or has already been established i.e. not 
during MM specific procedures or during IMSI detach procedure, see subclause 4.3.5. 

Initiated by the mobile station: 

IMSI detach procedure (with the exceptions specified in subclause 4.3.4). 

2) MM specific procedures: 

A MM specific procedure can only be initiated if no other MM specific procedure is running or no MM 
connection exists. The procedures belonging to this type are: 

normal location updating procedure; 

- periodic updating procedure; 
IMSI attach procedure; and 

- eCall inactivity procedure. 

3) MM connection management procedures: 

These procedures are used to establish, maintain and release a MM connection between the mobile station and the 
network, over which an entity of the upper CM layer can exchange information with its peer. A MM connection 
establishment can only be performed if no MM specific procedure is running. More than one MM connection may be 
active at the same time. 

Depending on how they can be initiated, three types of GMM procedures can be distinguished: 

1) GMM common procedures: 

In lu mode, a GMM common procedure can always be initiated whilst a PS signalling connection exists. 
The procedures belonging to this type are: 

Initiated by the network when a GMM context has been established: 

- P-TMSI (re-) allocation; 

GPRS authentication and ciphering; 

- GPRS identification; 
GPRS information. 

2) GMM specific procedures: 

Initiated by the network and used to detach the IMSI in the network for GPRS services and/or non-GPRS 
services and to release a GMM context: 

- GPRS detach. 

Initiated by the MS and used to attach or detach the IMSI in the network for GPRS services and/or non- 
GPRS services and to establish or release a GMM context: 

- GPRS attach and combined GPRS attach; 

- GPRS detach and combined GPRS detach. 

Initiated by the MS when a GMM context has been established: 

normal routing area updating and combined routing area updating; 

- periodic routing area updating. 
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3) GMM connection management procedures (lu mode only): 

Initiated by the MS and used to establish a secure connection to the network and/or to request the resource 
reservation for sending data: 

Service Request. 

The Service Request procedure can only be initiated if no MS initiated GMM specific procedure is ongoing. 



4.1 .1 .1 .1 Integrity Checking of Signalling Messages in the Mobile Station (lu mode only) 

In lu mode only, integrity protected signalling is mandatory with one exception regarding emergency calls (see 
subclause 4.1.1.1.1a). In lu mode only, all layer 3 protocols shall use integrity protected signalling once the security 
mode procedure has been successfully activated in the network and the MS. Integrity protection of all layer 3 signalling 
messages is the responsibility of lower layers. It is the network which activates integrity protection. This is done using 
the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). 

The supervision that integrity protection is activated shall be the responsibility of the MM and GMM layer in the MS 
(see 3GPP TS 33.102 [5a]). In order to do this, the lower layers shall provide the MM and GMM layer with an 
indication on when the integrity protection is activated in the MS (i.e. one indication to the MM layer when a security 
mode control procedure for the CS domain is processed successfully and one indication to the GMM layer when a 
security mode control procedure for the PS domain is processed successfully). 

The CS and PS domains in the network and the MM and GMM layers in the MS, are not aware of whether integrity 
protection has been started in the lower layers by the other domain. It is mandatory for the network to initiate one 
security mode control procedure for the CS domain and one for the PS domain. 

Except the messages listed below, no layer 3 signalling messages shall be processed by the receiving MM and GMM 
entities or forwarded to the CM entities, unless the network has activated the integrity protection for that domain. 

MM messages: 

- AUTHENTICATION REQUEST 

- AUTHENTICATION REJECT 

- IDENTITY REQUEST 

- LOCATION UPDATING ACCEPT (at periodic location update with no change of location area or 
temporary identity, and, any Per MS T3212 value is not changed) 

- LOCATION UPDATING REJECT (if the cause is not #25) 

- CM SERVICE ACCEPT, if the following two conditions apply: 

no other MM connection is established; and 

- the CM SERVICE ACCEPT is the response to a CM SERVICE REQUEST with CM SERVICE 
TYPE IE set to 'emergency call establishment' 

- CM SERVICE REJECT (if the cause is not #25) 

- ABORT 
GMM messages: 

- AUTHENTICATION & CIPHERING REQUEST 

- AUTHENTICATION & CIPHERING REJECT 

- IDENTITY REQUEST 

- ATTACH REJECT (if the cause is not #25) 

- ROUTING AREA UPDATE ACCEPT, if any of the following conditions appHes: 
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the MS performs periodic routing area updating with no change of routing area or temporary identity, 
and the T3312 extended value and the Network feature support value are not changed; 

the GMM entity in the MS has received an ATTACH ACCEPT message with neither ciphering nor 
integrity protection applied in response to an ATTACH REQUEST message with attach type set to 
"emergency attach"; or 

the MS has performed intersystem change from S 1 mode to lu mode with a PDN connection for 
emergency bearer services for which the "null integrity protection algorithm" EIAO has been used 
while in S 1 mode. 

- ROUTING AREA UPDATE REJECT (if the cause is not #25) 

- SERVICE REJECT (if the cause is not #25) 

- DETACH ACCEPT (for non power-off) 

- ATTACH ACCEPT, if the ATTACH ACCEPT is the response to an ATTACH REQUEST with attach 
type set to "emergency attach". 

SERVICE ACCEPT, if any of the following conditions applies: 

the GMM entity in the MS has received an ATTACH ACCEPT message with neither ciphering nor 
integrity protection applied in response to an ATTACH REQUEST message, with attach type set to 
"emergency attach"; or 

the MS has performed intersystem change from S 1 mode to lu mode with a PDN connection for 
emergency bearer services for which the "null integrity protection algorithm" EIAO has been used 
while in S 1 mode. 

CC messages: 

all CC messages, if the following two conditions apply: 

no other MM connection is established; and 

- the MM entity in the MS has received a CM SERVICE ACCEPT message with no ciphering or 

integrity protection applied as response to a CM SERVICE REQUEST message, with CM SERVICE 
TYPE set to 'Emergency call establishment' sent to the network.; or 

the MM connection was established locally due to the SRVCC handover of a PDN connection for 
emergency bearer services for which the "null integrity protection algorithm" EIAO has been used 
while in S 1 mode or for which integrity protection has not been activated while in lu mode. 

SM messages: 

all SM messages, if any of the following conditions applies: 

the GMM entity in the MS has received an ATTACH ACCEPT message with neither ciphering nor 
integrity protection applied in response to an ATTACH REQUEST message, with attach type set to 
"emergency attach"; or 

the MS has performed intersystem change from S 1 mode to lu mode with a PDN connection for 
emergency bearer services for which the "null integrity protection algorithm" EIAO has been used 
while in S 1 mode. 

Once integrity protection is activated, the receiving layer 3 entity in the MS shall not process any other layer 3 
signalling messages or any ATTACH ACCEPT message unless they have been successfully integrity checked by the 
lower layers. If any signalling messages, having not successfully passed the integrity check, are received, then the lower 
layers in the MS shall discard that message (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). If any layer 3 
signalling message is received, in either PS or CS domains, as not integrity protected even though the integrity 
protection has been activated in the MS by that domain in the network, then the lower layers shall discard this message 
(see 3GPPTS 25.331 [23c] and 3GPP TS 44.118 [111]). 

Integrity checking on the network side is performed by the RNC and is described in 3GPP TS 25.331 [23c] and 
3GPPTS 44.118 [111]. 
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4.1.1.1.1a Integrity protection for emergency call (lu mode only) 

The network should initiate the security mode procedure for an emergency call, in the same way as it would for any 
other call except in the cases defined in sub-clause "Security Procedures Not Applied" in 3GPP TS 33.102 [5a]. 

For the establishment of a MM connection for an emergency call when no other MM connection is established (e.g. for 
an emergency call initiated without a SIM/USIM no other MM connections can exist) the decision on whether or not to 
apply the security procedures shall be made by the network as defined in the subclause "Emergency Call Handling" in 
3GPPTS 33.102 [5a]. If the MM connection was estabhshed locally due to the SRVCC handover of a PDN connection 
for emergency bearer services for which the "null integrity protection algorithm" EIAO has been used while in S 1 mode 
or for which integrity protection has not been activated while in lu mode, the network need not apply the security 
procedures for this call. 

For an attach for emergency bearer services, (e.g. initiated without a SIM/USIM) the decision on whether or not to 
apply the security procedures shall be made by the network as defined in the subclause "Emergency Call Handling" in 
3GPP TS 33.102 [5a]. After intersystem change from SI mode to lu mode with a PDN connection for emergency bearer 
services for which the "null integrity protection algorithm" EIAO has been used while in S 1 mode, the network need not 
apply the security procedures for this connection. 

4.1 .1 .2 MM-GMM co-ordination for GPRS MS's 

4.1 .1 .2.1 GPRS MS operating in mode A or B in a network that operates in mode I 

If the network operates in mode I, GPRS MSes that operate in mode A or B and wish to be or are simultaneously IMSI 
attached for GPRS and non-GPRS services, shall use the combined GPRS attach and the combined and periodic routing 
area updating procedures instead of the corresponding MM specific procedures IMSI attach and normal and periodic 
location area updating. 

NOTE 1 : A GPRS MS operating in mode A or B in a network that operates in mode I, shall perform the combined 
GPRS attach or routing area update procedure regardless the value of the ATT flag. 

If a GPRS MS is operating in mode A or B in a network that operates in mode I the IMSI detach shall be performed by 
the GMM using the combined GPRS detach procedure. 

NOTE 2: A GPRS MS operating in mode A or B in a network that operates in mode I, shall perform the combined 
GPRS detach procedure regardless the value of the ATT flag. 

A GPRS MS operating in mode A or B in network that operates in mode I, shall use the combined GMM specific 
procedures in place of the MM specific procedures unless the re-activation of the MM specific procedures is explicitly 
described, so all conditions describing when to trigger an MM specific procedure listed in subclauses 4.3 and 4.4 shall 
not apply. 

A GPRS MS operating in mode A or B in a network that operates in mode I should not use any MM timers relating to 
MM specific procedures, (e.g. T3210, T3211, T3212, T3213) unless the re-activation of the MM specific procedures is 
explicitly described. If the MM timers are already running, the MS should not react on the expiration of the timers. 

NOTE 3: Whenever GMM performs a combined GMM procedure, a GPRS MS enters the MM state MM 

LOCATION UPDATING PENDING in order to prevent the MM from performing a location area 
updating procedure. 

If the authentication procedure is performed by MM and the authentication is rejected by the network (i.e. upon receive 
of AUTHENTICATION REJECT), the MS shall in addition set the GPRS update status to GU3 ROAMING NOT 
ALLOWED and shall, if available, delete the P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number stored. The SIM/USIM shall be considered as invalid for GPRS and non-GPRS services until switching off or 
the SIM/USIM is removed. The MS shall abort any GMM procedure and shall enter state GMM-DEREGISTERED. If 
SI mode is supported in the MS, the MS shall handle the EMM parameters EPS update status, GUTI, last visited 
registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the EPS authentication is not 
accepted by the network. 

If the PS or CS domain is barred because of domain specific access control, a GPRS MS operating in mode A or B in a 
network that operates in mode I shall act as if in network operation mode II or III (depending on whether a PCCCH is 
present in Gb-mode) and access to the barred domain shall be stopped entirely. If the MS detects that a domain is 
barred, this shall not trigger any MM or GMM specific procedure. 
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A GPRS MS operating in mode A or B in a network that operates in mode I shall perform a normal location updating 
procedure (in order to remove the Gs association in the MSC/VLR) when the following conditions are fulfilled: 

the GPRS MS has camped on a cell where the PS domain is barred and the CS domain is unbarred; and 

- T33 12, T33 1 1 , T3302, or T3330 expires; and 

for the last attempt to update the registration of the location area a combined GMM procedure was performed. 

Additionally the MS shall treat the expiry of T3312 when the PS domain changes from barred to unbarred, analogous to 
the descriptions for the cases when the timer expires out of coverage or in a cell that does not support GPRS (see 
subclause 4.7.2.2). 

If timer T3312 expires and both the PS and CS domain are barred, then a GPRS MS operating in mode A or B in a 
network that operates in mode I shall treat the expiry of T3312 when the GPRS MS detects that the PS or CS domain 
becomes unbarred, analogous to the descriptions for the cases when the timer expires out of coverage (see 
subclause 4.7.2.2). 

If the PS domain is barred and timer T3312 expires during an ongoing CS connection, then a GPRS MS operating in 
mode A or B in a network that operates in mode I shall treat the expiry of T3312 when the MM state MM -IDLE is 
entered, analogous to the descriptions for the cases when the timer expires out of coverage or in a cell that does not 
support GPRS (see subclause 4.7.2.2), or in a cell where the PS domain is barred. 

A GPRS MS operating in mode A or B in a network that operates in mode I shall perform a combined routing area 
update procedure indicating "combined RA/LA updating with IMSI attach" (in order to establish the Gs association in 
the MSC/VLR) when the following conditions are fulfilled: 

the GPRS MS detects that CS or PS domain or both change from barred to unbarred; 

as a result of the change of the domain specific barring status, both domains are unbarred; and 

for the last attempt to update the registration of the location area an MM specific procedure was performed (see 
subclause 4.7.5.2.1) or for the last attempt to update the registration of the routing area a normal routing area 
update was performed. 

4.1 .1 .2.2 GPRS MS operating in mode A or B in a network that operates in mode II or III 

If the network operates in mode II or III, a GPRS MSs that operate in mode A or B and wish to be or are simultaneously 
IMSI attached for GPRS and non-GPRS services, shall use the MM specific procedures listed in subclauses 4.3 and 4.4 
and the GMM specific procedures listed in subclauses 4.7.3, 4.7.4 and 4.7.5. The applicability of periodic location 
updating is further specified in subclause 4.4.2 and the periodic routing area updating is specified in subclause 4.7.2.2. 

If the authentication procedure is performed by MM and the authentication is rejected by the network (i.e upon receive 
of AUTHENTICATION REJECT), the MS shall in addition set the GPRS update status to GU3 ROAMING NOT 
ALLOWED and shall, if available, delete the P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number stored. The SIM/USIM shall be considered as invalid for GPRS and non-GPRS services until switching off or 
the SIM/USIM is removed. The MS shall abort any GMM procedure and shall enter state GMM-DEREGISTERED. If 
SI mode is supported in the MS, the MS shall handle the EMM parameters EPS update status, GUTI, last visited 
registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the EPS authentication is not 
accepted by the network. 

If the PS or CS domain is barred because of domain specific access control, a GPRS MS operating in mode A or B in a 
network that operates in mode II or III shall use the MM specific procedures or GMM specific procedures, respectively, 
in the domain which is unbarred. If the MS detects that a domain changes from barred to unbarred, it shall behave as 
specified in subclauses 4.3.4.4, 4.4.4.9, 4.5.1.2, 4.7.3.1.5, 4.7.4.1.4, 4.7.5.1.5, and 4.7.13.5. 

4.1 .1 .2A Coordination between GMM and EMM 

See subclause 5.1.4 in 3GPP TS 24.301 [120]. 

4.1 .1 .3 Core Network System Information for MM (lu mode only) 

In the network broadcast system information some of the system information is used by MM. 
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At reception of new system information, the RRC layer in the MS delivers the contents of the CN common system 
information and the CS domain specific system information to the MM layer in the MS. 

The Core Network system information is included in specific information elements within some RRC messages sent to 
MS (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). In the Core Network system information the Common 
system information part and the CS domain specific system information part contains settings of parameters controlling 
MM functionality. No MM messages contain the Core Network System Information. 

4.1 .1 .4 Core Network System Information for GMM (lu mode only) 

4.1.1.4.1 General 

In the network broadcast system information some of the system information is used by GMM. 

At reception of new system information, the RRC layer in the MS delivers the contents of the CN common system 
information and the PS domain specific system information to the GMM layer in the MS. 

The Core Network system information is included in specific information elements within some RRC messages sent to 
MS (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). In the Core Network system information the Common 
system information part and the PS domain specific system information part contains settings of parameters controlling 
GMM functionality. No GMM messages contain the Core Network System Information. 

4.1 .1 .4.2 Control of Network Mode of Operation I 

The behaviour of the MS with respect to NMO I is determined by the combination of PS domain specific system 
information IE as defined in subclause 10.5.1.12.3 and the setting of the parameter "NMO_I_Behaviour" in the NAS 
configuration Management Object as specified in 3GPP TS 24.368 [135] or in USIM file NAScqnfig as specified in 
3GPPTS 31.102 [112]: 

if the parameter "NMO_I_Behaviour" in the NAS configuration Management Object is set to the value of "1", 
the bit 2 "NMO I" of system information as described in figure 10.5.1.12.3/table 10.5.1.12.3 is applied; or 

if the parameter "NMO_I_Behaviour" in the NAS configuration Management Object is set to the value of zero or 
is not provisioned, the bit 1 "NMO" of system information as described in figure 10.5.1.12.3/table 10.5.1.12.3 is 
applied. 

4.1.1.5 Access class control 

The network can restrict the access for certain groups of mobile stations. These groups are also known as access classes. 

The restriction can apply for access to both domains (common access class control or EAR, depending on EAR 
configuration) or to one domain only (domain specific access control) (see 3GPP TS 23.122 [14]). 

Additionally, the network can alleviate the access restriction in both domains or domain specifically, and allow 
restricted mobile stations to respond to paging messages or to perform generic location updating, or GPRS attach or 
routing area updating procedure. 

A network operator can also restrict some MSs to access the network for location registration, although via common 
access class control or domain specific access class control the MSs are permitted to access the network for other 
purposes. Therefore, for each access to the network the mobile station shall determine from the information received via 
the system information broadcast whether access is allowed or not: 

For paging response the mobile station shall evaluate the control information for common access control (as 
specified in 3GPP TS 44.018 [84], 3GPP TS 44.060 [76], and 3GPP TS 25.331 [23c]), domain specific access 
control (as specified in 3GPP TS 25.331 [23c]), and the specific control information for paging response (as 
specified in 3GPP TS 25.331 [23c]; see "Paging Permission with Access Control"). 

For generic location updating, GPRS attach and routing area updating procedures the mobile station shall 
evaluate the control information for: 

- common access control (as specified in 3GPP TS 44.018 [84], 3GPP TS 44.060 [76], and 
3GPPTS 25.331 [23c]); 
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domain specific access control (as specified in 3GPP TS 25.331 [23c]); 

specific control information for location registration (as specified in 3GPP TS 25.331 [23c]; see "Paging 
Permission with Access Control"); and 

- EAB as specified in 3GPP TS 44.018 [84] and 3GPP TS 44.060 [76]. 

The same control information shall also be taken into account, when the present document requires the mobile 
station to initiate a generic location updating, or GPRS attach or routing area updating procedure when it detects 
that a domain changes from barred to unbarred (see e.g. subclauses 4.1.1.2.1 and 4.1.1.2.2). 

For all other purposes the mobile station shall evaluate the control information for common access control as 
specified in 3GPP TS 44.018 [84], 3GPP TS 44.060 [76], and 3GPP TS 25.331 [23c], the control information for 
EAB (as specified in 3GPP TS 44.018 [84] and 3GPP TS 44.060 [76]) and domain specific access control (as 
specified in 3GPP TS 25.331 [23c]). 

In this version of the specification EAB is specified for A/Gb mode only. 

4.1 .1 .6 Specific requirements for MS configured to use timer T3245 

The following requirement applies for an MS that is configured to use timer T3245 (see 3GPP TS 24.368 [135] or 
3GPPTS 31.102 [112]): 

When the MS adds a PLMN identity to the "forbidden PLMN list" or the "forbidden PLMNs for GPRS service" list or 
sets the SIM/USIM as invalid for non-GPRS services or GPRS services or both, and timer T3245 is not running, the MS 
shall start timer T3245 with a random value, uniformly drawn from the range between 24h and 48h. 

Upon expiry of the timer T3245, the MS shall erase the "forbidden PLMN Ust" and the "forbidden PLMNs for GPRS 
service" list and set the SIM/USIM to valid for non-GPRS services and GPRS services. When the lists are erased, the 
MS performs a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

If the MS is switched off when the timer T3245 is running, the MS shall behave as follows when the MS is switched on: 

let tl be the time remaining for T3245 timeout at switch off and let t be the time elapsed between switch off and 
switch on. If tl is greater than t, then the timer shall be restarted with the value tl - t. If tl is equal to or less than 
t, then the MS will follow the behaviour as defined in the paragraph above upon expiry of the timer T3245. If the 
MS is not capable of determining t, then the MS shall restart the timer with the value tl. 

4.1 .1 .7 Handling of NAS level mobility management congestion control 

The network may detect GMM or MM signalling congestion and perform NAS level mobility management congestion 
control. PS domain NAS level mobility management congestion control consists of general NAS level mobility 
management congestion control and subscribed APN based congestion control. CS domain NAS level mobility 
management congestion control consists of general NAS level mobility management congestion control. 

Under NAS level mobility management congestion control the network may reject mobility management signalling 
requests from MSs. The network should not reject requests for emergency bearer services. When general NAS level 
mobility management congestion control is active, the network may reject messages including the NAS signalling low 
priority indicator before rejecting messages without the NAS signalling low priority indicator. 

When subscribed APN based congestion control is active for a particular APN, the network may reject attach request 
from MSs with subscription to this APN. 

In mobility management the network may detect NAS signalling congestion. The network may start or stop performing 
the subscribed APN based congestion control based on mobility management level criteria such as: 

rate of mobility management NAS messages from a group of MSs with a subscription to a particular APN 
exceeds or falls below certain thresholds; or 

setting in network management. 

When the NAS level mobility management congestion control is active, the network may include a value for the 
mobility management back-off timer T3246 or T3346 in the reject messages. The MS starts the mobility management 
backoff timer with the value received in the mobility management reject messages. To avoid that large numbers of MSs 
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simultaneously initiate deferred requests, the network should select the value for the mobility management backoff 
timer for the rejected MSs so that timeouts are not synchronised. 

For subscribed APN based congestion control the backoff timer value for a particular APN may be APN dependent. 

If the MS is switched off when the timers T3246 or T3346 are running, the MS shall behave as follows for each of these 
timers when the MS is switched on: 

let tl be the time remaining untiltimeout at switch off and let t be the time elapsed between switch off and switch 
on. If tl is greater than t, then the timer shall be restarted with the value tl - 1. If tl is equal to or less than t, then 
the timer need not be restarted. If the MS is not capable of determining t, then the MS shall restart the timer with 
the value tl. 

If the MS enters a new PLMN which is not in the list of equivalent PLMNs, it shall stop timers T3246 and T3346, if 
running, when initiating mobility management procedures in the new PLMN. 

4.1 .2 MM sublayer states 

The description of the states for the MM sublayer is organized as follows. The main states for the MS side, related to 
the procedures, are described in subclause 4.1.2.1.1. The MM IDLE state is subdivided in substates for the description 
of the behaviour in idle mode (subclause 4.1.2.1.2). This behaviour depends on an update status, described in 
subclause 4.1.2.2. The states for the network side are described in subclause 4.1.2.3. 

4.1 .2.1 MM sublayer states in the mobile station 

In this subclause, the possible states for the MM sublayer in the mobile station is described. In figure 4. 1 of the present 
document, an overview of the MM sublayer protocol is given. 

4.1.2.1.1 Main States 

NULL 

The mobile station is inactive (e.g. power down). Important parameters are stored. Only manual action by the 
user may transfer the MM sublayer to another state. 

3 LOCATION UPDATING INITIATED 

A location updating procedure has been started and the MM awaits a response from the network. The timer 
T3210 is running. 

5 WAIT FOR OUTGOING MM CONNECTION 

The MM connection establishment has been started, and the MM awaits a response from the network. The 
timer T3230 is running. 

6 MM CONNECTION ACTIVE 

The MM sublayer has a RR connection to its peer entity on the network side. One or more MM connections 
are active. 

7 IMSI DETACH INITIATED 

The IMSI detach procedure has been started. The timer T3220 is running. 

8 PROCESS CM SERVICE PROMPT 

The MM sublayer has a RR connection to its peer entity on the network side. The Mobile Station has 
received a CM SERVICE PROMPT message but has not yet responded $(CCBS)$. 

9 WAIT FOR NETWORK COMMAND 

The MM sublayer has a RR connection to its peer entity in the network, but no MM connection is 
established. The mobile station is passive, awaiting further commands from the network. The timer T3240 
may be running. 
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10 LOCATION UPDATE REJECTED 

A location updating procedure has been rejected and RR connection release is awaited. The timer T3240 is 
running. 
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Figure 4.1a/3GPP TS 24.008: Overview mobility management protocol/IUIS Side 
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Additions to Figure 4.1.a/3GPP TS 24.008 

13. WAIT FOR RR CONNECTION (LOCATION UPDATING) 

The MM sublayer has requested RR connection establishment for starting the location updating procedure. 

14. WAIT FOR RR CONNECTION (MM CONNECTION) 

The MM sublayer has requested RR connection establishment for dedicated mode for starting the MM 
connection establishment. 

15. WAIT FOR RR CONNECTION (IMSI DETACH) 

The MM sublayer has requested RR connection establishment for starting the IMSI detach procedure. 
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17. WAIT FOR REESTABLISH 

A lower layer failure has occurred and re-establishment may be performed from the disturbed CM layer 
entities. 

18. WAIT FOR RR ACTIVE 

The MM sublayer has requested activation of the RR sublayer. 

19. MM IDLE 

There is no MM procedure running and no RR connection exists except that a local MM context may exist 
when the RR sublayer is in Group Receive mode. This is a compound state, and the actual behaviour of the 
mobile station to Connection Management requests is determined by the actual substate as described 
hereafter. 

20. WAIT FOR ADDITIONAL OUTGOING MM CONNECTION. 

The MM connection establishment for an additional MM connection has been started, and the MM awaits 
response from the network. 

21. MM CONNECTION ACTIVE (GROUP TRANSMIT MODE) 

(Only applicable for mobile stations supporting VGCS talking:) The MM sublayer has a RR connection on 
the VGCS channel to its peer entity on the network side. Only one MM connection is active. 

22. WAIT FOR RR CONNECTION (GROUP TRANSMIT MODE) 

(Only applicable for mobile stations supporting VGCS talking:) The MM sublayer has requested to perform 
an uplink access on the VGCS channel. 

23. LOCATION UPDATING PENDING 

(Only applicable for GPRS MS operation modes A and B; not shown in figure 4.1a) A location updating has 
been started using the combined GPRS routing area updating procedure. 

24. IMSI DETACH PENDING 

(Only applicable for GPRS MS operation modes A and B; not shown in figure 4.1a) An IMSI detach for non- 
GPRS services has been started using the combined GPRS detach procedure at not switching off. 

25. RR CONNECTION RELEASE NOT ALLOWED 

(Only applicable for mobile stations supporting RRLP procedures (see 3GPP TS 44.031 [23b]) or LCS 
procedures over RRC (see 3GPP TS 25.331 [23c])). All MM connections are released by their CM entities, 
but the RR connection is maintained by the network due to an ongoing RRLP procedure or LCS procedure 
over RRC. 

4.1 .2.1 .2 Substates of the MM IDLE state 

For the description of the behaviour of the MS the MM IDLE state is subdivided in several substates, also called the 
service states. The service state pertains to the whole MS (ME alone if no SIM/USIM is inserted, or ME plus 
SIM/USIM). The service state depends on the update status (see subclause 4.1.2.2) and on the selected cell. 

19.1 NORMAL SERVICE 

Valid subscriber data are available, update status is Ul, a cell is selected that belongs to the LA where the 
subscriber is registered. 

In this state, all requests from the CM layers are treated normally. 

19.2 ATTEMPTING TO UPDATE 

Valid subscriber data are available, update status is U2 and a cell is selected. Requests from upper layers are 
accepted. Emergency call requests are treated normally, otherwise the request triggers first a location 
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updating attempt in the selected cell, and then triggers the needed procedure only in case of successful 
location updating, otherwise the request is rejected. 

19.3 LIMITED SERVICE 

Valid subscriber data are available, update status is U3, and a cell is selected, which is known not to be able 
to provide normal service. Only emergency services are offered. 

19.4 NO IMSI 

No valid subscriber data (no SIM/USIM, or the SIM/USIM is not considered valid by the ME), and a cell is 
selected. Only emergency services are offered. 

19.5 NO CELL AVAILABLE 

No cell can be selected. This state is entered after a first intensive search failed (state 19.7). Cells are 
searched at a low rhythm. 

This state is also entered when S 1 mode is activated in the MS and current cell is an E-UTRAN cell. No services, 
except those provided by CS fallback and SMS over SGs, are offered. 

19.6 LOCATION UPDATE NEEDED 

Valid subscriber data are available, and for some reason a location updating must be done as soon as possible 
(for instance update status is Ul but the selected cell is not in the registered LA, or the timer has expired). 
This state is usually of no duration, but can last, e.g. due to access class control, (see subclause 4.1.1.2.1). 

19.7 PLMN SEARCH 

The mobile station is searching for PLMNs, and the conditions for state 19.8 are not met. This state is ended 
when either a cell is selected (the new state is 19.1, 19.3 or 19.6), or when it is concluded that no cell is 
available for the moment (the new state is 19.5). 

19.8 PLMN SEARCH, NORMAL SERVICE 

Valid subscriber data are available, update status is Ul, a cell is selected which belongs to the LA where the 
subscriber is registered, and the mobile station is searching for PLMNs. This state is ended when either a cell 
is selected (the new state is 19.1, 19.3 or 19.6), or when it is concluded that no cell is available for the 
moment (the new state is 19.5). 

19.9 RECEIVING GROUP CALL (NORMAL SERVICE) 

Only applicable for mobile stations supporting VGCS listening or VBS listening. Valid subscriber data are 
available, update status is Ul, a VGCS channel or VBS channel is received in a cell that belongs to the LA 
where the subscriber is registered. 

In this state, only requests from the GCC or BCC layers are treated. 

19.10 RECEIVING GROUP CALL (LIMITED SERVICE) 

Only applicable for mobile stations supporting VGCS listening or VBS listening. Valid subscriber data are 
available, update status is U3, a VGCS channel or VBS channel is received in a cell which is known not to be 
able to provide normal service. 

In this state, only requests from the GCC or BCC layers for the reception of VGCS or VBS calls are treated 
and group call emergency services are offered. 

19.1 1 eCALL INACTIVE 

Valid subscriber data are available, update status is U4, and a cell is selected, which is expected to be able to 
provide normal service. Only emergency services and test/reconfiguration calls[8] can be initiated by the 
mobile station. This state is applicable only to an eCall only mobile station (as determined by information 
configured in USIM). The state is entered by the mobile station in order to avoid MM activity and MM 
signalling in the absence of an emergency call or test/reconfiguration call. The state is ended when an 
emergency services or test/reconfiguration calls[8] is initiated by the mobile station, the new state depends on 
the result of the procedure when returning to MM-IDLE described in subclause 4.2.3. 
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4.1 .2.2 The update Status 

In parallel with the sublayer states described in subclause 4. 1 .2. 1 and which control the MM sublayer protocol, an 
update status exists. 

The update status pertains to a specific subscriber embodied by a SIM/USIM. This status is defined even when the 
subscriber is not activated (SIM/USIM removed or connected to a switched-off ME). It is stored in a non volatile 
memory in the SIM/USIM. The update status is changed only as a result of a location updating procedure attempt (with 
the exception of an authentication failure and of some cases of CM service rejection). In some cases, the update status is 
changed as a result of a GPRS attach, GPRS routing area update, service request or network initiated GPRS detach 
procedure. 

Ul UPDATED 

The last location updating attempt was successful (correct procedure outcome, and the answer was 
acceptance from the network). With this status, the SIM/USIM contains also the LAI of the LA where the 
subscriber is registered, and possibly valid TMSI, GSM ciphering key, UMTS integrity key, UMTS ciphering 
key and ciphering key sequence number. Furthermore, if the ME supports any A5 ciphering algorithm that 
requires a 128-bit ciphering key and a USIM is in use, then the ME may contain a valid GSM Kci28. The 
"Location update status" stored on the SIM/USIM shall be "updated". 

U2 NOT UPDATED 

The last location updating attempt made failed procedurally (no significant answer was received from the 
network, including the cases of failures or congestion inside the network). 

For this status, the SIM/USIM does not contain any valid LAI, TMSI, GSM ciphering key, UMTS integrity 
key, UMTS ciphering key or ciphering key sequence number. For compatibility reasons, all these fields shall 
be set to the "deleted" value at the moment the status is set to NOT UPDATED. However the presence of 
other values shall not be considered an error by the mobile station. Furthermore, if the ME supports any A5 
ciphering algorithm that requires a 128-bit ciphering key and a USIM is in use, then the ME shall delete the 
GSM Kci28 stored at the moment the status is set to NOT UPDATED. The "Location update status" stored on 
the SIM/USIM shall be "not updated". 

U3 ROAMING NOT ALLOWED 

The last location updating attempt run correctly, but the answer from the network was negative (because of 
roaming or subscription restrictions). 

For this status, the SIM/USIM may contain a valid LAI, TMSI, GSM ciphering key, UMTS integrity key, 
UMTS ciphering key or ciphering key sequence number. For compatibility reasons, all these fields shall be 
set to the "deleted" value if the LAI is deleted. However the presence of other values shall not be considered 
an error by the mobile station. Furthermore, if the ME supports any A5 ciphering algorithm that requires a 
128-bit ciphering key and a USIM is in use, then the ME shall delete the GSM Kci28 stored if the LAI is 
deleted. The "Location update status" stored on the SIM/USIM shall be "Location Area not allowed". 

U4 UPDATING DISABLED 

Location updating has been disabled. 

For this status, the SIM/USIM does not contain any valid LAI, TMSI, GSM ciphering key, UMTS integrity 
key, UMTS ciphering key or ciphering key sequence number. For compatibility reasons, all these fields shall 
be set to the "deleted" value at the moment the status is set to eCALL INACTIVE. However the presence of 
other values shall not be considered an error by the mobile station. Furthermore, if the ME supports any A5 
ciphering algorithm that requires a 128-bit ciphering key and a USIM is in use, then the ME shall delete the 
GSM Kci28 stored at the moment the status is set to eCALL INACTIVE. The "Location update status" stored 
on the SIM/USIM shall be "not updated". 

4.1 .2.3 MM sublayer states on the network side 

l.IDLE 

The MM sublayer is not active except possibly when the RR sublayer is in Group Receive mode. 
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2. WAIT FOR RR CONNECTION 

The MM sublayer has received a request for MM connection establishment from the CM layer. A RR 
connection to the mobile station is requested from the RR sublayer (i.e. paging is performed). 

3. MM CONNECTION ACTIVE 

The MM sublayer has a RR connection to a mobile station. One or more MM connections are active, or no 
MM connection is active but an RRLP procedure or LCS procedure over RRC is ongoing. 

4. IDENTIFICATION INITIATED 

The identification procedure has been started by the network. The timer T3270 is running. 

5. AUTHENTICATION INITIATED 

The authentication procedure has been started by the network. The timer T3260 is running. 

6. TMSI REALLOCATION INITIATED 

The TMSI reallocation procedure has been started by the network. The timer T3250 is running. 

7. SECURITY MODE INITIATED 

In lu mode, the security mode setting procedure has been requested to the RR sublayer. In A/Gb mode, the 
cipher mode setting procedure has been requested to the RR sublayer. 

8a. WAIT FOR MOBILE ORIGINATED MM CONNECTION 

A CM SERVICE REQUEST message is received and processed, and the MM sublayer awaits the "opening 
message" of the MM connection. 

8b. WAIT FOR NETWORK ORIGINATED MM CONNECTION 

A CM SERVICE PROMPT message has been sent by the network and the MM sublayer awaits the "opening 
message" of the MM connection $(CCBS)$. 

9. WAIT FOR REESTABLISHMENT 

The RR connection to a mobile station with one or more active MM connection has been lost. The network 
awaits a possible re-establishment request from the mobile station. 

10. WAIT OF A GROUP CALL 

Only applicable in case for mobile station supporting VGCS talking. The MM sublayer has received a 
request for establishing a VGCS from the GCC sublayer. The request for establishing a VGCS channels is 
given to the RR sublayer. 

11. GROUP CALL ACTIVE 

Only applicable in case of mobile station supporting VGCS talking. A VGCS channel is established by the 
RR sublayer. An RR connection to the talking mobile station can be established by the RR sublayer on the 
VGCS channel. The MM sublayer is active but no sending of MM message between the network and the 
mobile station has occurred. 

12. MM CONNECTION ACTIVE (GROUP CALL) 

Only applicable in case of mobile station supporting VGCS talking. The MM sublayer has a RR connection 
to the talking mobile station on the VGCS channel. Only one MM connection is active. 

13. WAIT FOR BROADCAST CALL 

Only applicable in case of VBS. The MM sublayer has received a request for a VBS establishment from the 
BCC sublayer. The request for establishment of VBS channels is given to the RR sublayer. 

14. BROADCAST CALL ACTIVE 
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Only applicable in case of VBS. A VBS channel is established by the RR sublayer. The MM sublayer is 
active but no explicit MM establishment between the Network and the mobile station has occurred. 

4.1 .3 GPRS mobility management (GMM) sublayer states 

In this subclause, the GMM protocol of the MS and the network are described by means of two different state machines. 
In subclause 4.1.3.1, the states of the GMM entity in the MS are introduced. The behaviour of the MS depends on a 
GPRS update status that is described in subclause 4.1.3.2. The states for the network side are described in 
subclause 4.1.3.3. 

4.1 .3.1 GMM states in the MS 

In this subclause, the possible GMM states are described of a GMM entity in the mobile station, subclause 4.1.3.1.1 
summarises the main states of a GMM entity, see figure 4.1b of the present document. The substates that have been 
defined are described in subclause 4.1.3.1.2 and subclause 4.1.3.1.3. 

However, it should be noted that this subclause does not include a description of the detailed behaviour of the MS in the 
single states and does not cover abnormal cases. Thus, figure 4.1b of the present document is rather intended to give an 
overview of the state transitions than to be a complete state transition diagram. A detailed description of the behaviour 
of the MS is given in subclause 4.2. Especially, with respect to the behaviour of the MS in abnormal cases it is referred 
to subclause 4.7. 

4.1.3.1.1 Main states 

4.1.3.1.1.1 GMM-NULL 

The GPRS capability is disabled in the MS. No GPRS mobility management function shall be performed in this state. 

4.1.3.1.1.2 GMM-DEREGISTERED 

The GPRS capability has been enabled in the MS, but no GMM context has been established. In this state, the MS may 
establish a GMM context by starting the GPRS attach or combined GPRS attach procedure. 

4.1 .3.1 .1 .3 GMM-REGISTERED-INITIATED 

A GPRS attach or combined GPRS attach procedure has been started and the MS is awaiting a response from the 
network. 

4.1.3.1.1.4 GMM-REGISTERED 

A GMM context has been established, i.e. the GPRS attach or combined GPRS attach procedure has been successfully 
performed. In this state, the MS may activate PDP contexts, MBMS contexts, may send and receive user data and 
signalling information and may reply to a page request. Furthermore, cell and routing area updating are performed. 

4.1 .3.1 .1 .5 GMM-DEREGISTERED-INITIATED 

The MS has requested release of the GMM context by starting the GPRS detach or combined GPRS detach procedure. 
This state is only entered if the MS is not being switched off at detach request. 

4.1 .3.1 .1 .6 GMM-ROUTING-AREA-UPDATING-INITIATED 

A routing area updating procedure has been started and the MS is awaiting a response from the network. 

4.1 .3.1 .1 .7 GMM-SERVIGE-REQUEST-INITIATED (lu mode only) 

A service request procedure has been started and the MS is awaiting a response from the network. 
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4.1 .3.1 .2 Substates of state GMM-DEREGISTERED 

The GMM-DEREGISTERED state is subdivided into several substates as explained below. The substates pertain to the 
whole MS (ME alone if no SIM/USIM is inserted, or ME plus SIM/USIM). The selection of the appropriate substate 
depends on the GPRS update status, see subclause 4.1.3.2, and on the selected cell. 

4.1 .3.1 .2.1 GMM-DEREGISTERED.NORMAL-SERVICE 

Valid subscriber data is available, the GPRS update status is GUI or GU2, a suitable cell has been found and the PLMN 
or LA is not in the forbidden list. In this state, a request for GPRS attach is performed using the stored temporary 
mobile subscriber identity for GPRS (P-TMSI), routing area identification (RAI) and GPRS ciphering key sequence 
number in case of GUI. If the GPRS update status is GU2, the IMSI shall be used to attach for GPRS services. 

4.1 .3.1 .2.2 GMM-DEREGISTERED. LIMITED-SERVICE 

Valid subscriber data is available, GPRS update status is GU3, and a cell is selected, which is known not to be able to 
provide normal service. 

4.1 .3.1 .2.3 GMM-DEREGISTERED.ATTAGH-NEEDED 

Valid subscriber data is available and for some reason a GPRS attach must be performed as soon as possible. This state 
is usually of no duration, but can last, e.g. due to access class control (see subclause 4.1.1.2.1). 

4.1 .3.1 .2.4 GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH 

The GPRS update status is GU2, a cell is selected, a previous GPRS attach was rejected. The execution of further attach 
procedures depends on the GPRS attach attempt counter. No GMM procedure except GPRS attach shall be initiated by 
the MS in this substate. 

4.1 .3.1 .2.5 GMM-DEREGISTERED. NO-IMSI 

No valid subscriber data is available (no SIM/USIM, or the SIM/USIM is not considered valid by the ME) and a cell 
has been selected. 

4.1 .3.1 .2.6 GMM-DEREGISTERED. NO-GELL-AVAILABLE 

No cell can be selected. This substate is entered after a first intensive search failed (substate PLMN SEARCH). Cells 
are searched for at a low rhythm. No services are offered. 

4.1 .3.1 .2.7 GMM-DEREGISTERED. PLMN-SEARCH 

The mobile station is searching for PLMNs. This substate is left either when a cell has been selected (the new substate 
is NORMAL-SERVICE or LIMITED-SERVICE) or when it has been concluded that no cell is available at the moment 
(the new substate is NO-CELL-AVAILABLE). 

4.1 .3.1 .2.8 GMM-DEREGISTERED. SUSPENDED (A/Gb mode only) 

The MS shall enter this substate when entering dedicated mode and the MS limitations make it unable to communicate 
on GPRS channels. The MS shall leave this substate when leaving dedicated mode. 

4.1 .3.1 .3 Substates of state GMM-REGISTERED 

The state GMM-REGISTERED is subdivided into several substate as explained below. The substates pertain to the 
whole MS (ME alone if no SIM/USIM is inserted, or ME plus SIM/USIM). 

4.1 .3.1 .3.1 GMM-REGISTERED.NORMAL-SERVIGE 

User data and signalling information may be sent and received. 
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4.1 .3.1 .3.2 GMM-REGISTERED. SUSPENDED (A/Gb mode only) 

The MS shall enter this substate when entering dedicated mode and when the MS limitations makes it unable to 
communicate on GPRS channels. In this substate, no user data should be sent and no signalling information shall be 
sent. The MS shall leave this substate when leaving dedicated mode. 

4.1 .3.1 .3.3 GMM-REGISTERED. UPDATE-NEEDED 

The MS has to perform a routing area updating procedure, but its access class is not allowed in the cell due to access 
class control (see subclause 4.1.1.2.1). The procedure will be initiated as soon as access is granted (this might be due to 
a cell-reselection or due to change of the access classes allowed in the current cell). No GMM procedure except routing 
area updating shall be initiated by the MS in this substate. In this substate, no user data and no signalling information 
shall be sent. 

4.1 .3.1 .3.4 GMM-REGISTERED.ATTEMPTING-TO-UPDATE 

A routing area updating procedure failed due to a missing response from the network. The MS retries the procedure 
controlled by timers and a GPRS attempt counter. No GMM procedure except routing area updating shall be initiated by 
the MS in this substate. No data shall be sent or received. 

4.1 .3.1 .3.5 GMM-REGISTERED. NO-GELL-AVAILABLE 

GPRS coverage has been lost. In this substate, the MS shall not initiate any GMM procedures except of cell (and 
PLMN) reselection. 
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4.1.3.1.3.6 



Figure 4.1b/3GPP TS 24.008:GMM main states in the IVIS 



GMM-REGISTERED. LIMITED-SERVICE 



A cell is selected, which is known not to be able to provide normal service. The MS will remain in this sub-state until a 
cell is selected which is able to provide normal service. 



4.1.3.1.3.7 



GMM-REGISTERED.ATTEMPTING-TO-UPDATE-MM 



A combined routing area updating procedure or a combined GPRS attach procedure was successful for GPRS services 
only. The MS retries the procedure controlled by timers and a GPRS attempt counter. User data and signalling 
information may be sent and received. 



4.1.3.1.3.8 



GMM-REGISTERED.IMSI-DETAGH-INITIATED 



The MS performs a combined GPRS detach procedure for non-GPRS services only (detach type "IMSI Detach"). This 
state is entered if the MS is attached for GPRS and non-GPRS services in a network that operates in network mode I 
and wants to detach for non-GPRS services only. User data and signalling information may be sent and received. 



4.1.3.1.3.9 



GMM-REGISTERED. PLMN-SEARGH 



The mobile station is searching for PLMNs. This substate is left either when a cell has been selected (the new substate 
is NORMAL-SERVICE or LIMITED-SERVICE) or when it has been concluded that no cell is available at the moment 
(the new substate is NO-CELL-AVAILABLE). 
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4.1 .3.2 GPRS update status 

In addition to the GMM sublayer states described so far, a GPRS update status exists. 

The GPRS update status pertains to a specific subscriber embodied by a SIM/USIM. This status is defined even when 
the subscriber is not activated (SIM/USIM removed or connected to a switched off ME). It is stored in a non volatile 
memory in the SIM/USIM. The GPRS update status is changed only after execution of a GPRS attach, network initiated 
GPRS detach, authentication procedure, or routing area updating procedure. 

GUI: UPDATED 

The last GPRS attach or routing area updating attempt was successful (correct procedure outcome, and the 
answer was accepted by the network). The SIM/USIM contains the RAI of the routing area (RA) to which the 
subscriber was attached, and possibly a valid P-TMSI, GPRS GSM ciphering key, GPRS UMTS ciphering key, 
GPRS UMTS integrity key and GPRS ciphering key sequence number. Furthermore, if the ME supports any 
GEA ciphering algorithm that requires a 128-bit ciphering key and a USIM is in use, then the ME may contain a 
vahd GPRS GSM Kcng. 

GU2: NOT UPDATED 

The last GPRS attach or routing area updating attempt failed procedurally, i.e. no response was received from 
the network. This includes the cases of failures or congestion inside the network. 

In this case, the SIM/USIM may contain the RAI of the routing area (RA) to which the subscriber was attached, 
and possibly also a valid P-TMSI, GPRS GSM ciphering key, GPRS UMTS ciphering key, GPRS UMTS 
integrity key and GPRS ciphering key sequence number. For compatibility reasons, all these fields shall be set to 
the "deleted" value if the RAI is deleted. However, the presence of other values shall not be considered an error 
by the MS. Furthermore, if the ME supports any GEA ciphering algorithm that requires a 128-bit ciphering key 
and a USIM is in use, then the ME shall delete the GPRS GSM Kci28 stored if the RAI is deleted. 

GU3: ROAMING NOT ALLOWED 

The last GPRS attach or routing area updating attempt was correctly performed, but the answer from the network 
was negative (because of roaming or subscription restrictions). 

In this case, the SIM/USIM may contain the RAI of the routing area (RA) to which the subscriber was attached, 
and possibly also a valid P-TMSI, GPRS GSM ciphering key, GPRS UMTS ciphering key, GPRS UMTS 
integrity key or GPRS ciphering key sequence number. For compatibility reasons, all these fields shall be set to 
the value "deleted" if the RAI is deleted. However, the presence of other values shall not be considered an error 
by the MS. Furthermore, if the ME supports any GEA ciphering algorithm that requires a 128 -bit ciphering key 
and a USIM is in use, then the ME shall delete the GPRS GSM Kci28 stored if the RAI is deleted. 

If the MS is attached for emergency bearer services, the MS shall not store the GMM parameters described in this 
subclause on the SIM/USIM or in non-volatile memory. Instead the MS shall temporarily store these parameters locally 
in the ME and the MS shall delete these parameters when the MS is detached. 

4.1 .3.3 GMM mobility management states on the network side 

In this subsubclause, the possible states are described for the GMM on the network side. Subclause 4.1.3.3.1 
summarises the main states. The corresponding substates are described in subclause 4.1.3.3.2. 

However, it should be noted that this subclause does not include a description of the detailed behaviour of the network 
in the single states and does not cover abnormal cases. Thus, figure 4.1c/3GPP TS 24.008 is rather intended to give an 
overview of the state transitions than to be a complete state transition diagram. A detailed description of the behaviour 
of the MS is given in subclause 4.2. Especially, with respect to the behaviour of the MS in abnormal cases it is referred 
to subclause 4.7. 

4.1.3.3.1 Main States 

4.1.3.3.1.1 GMM-DEREGISTERED 

The network has no GMM context or the GMM context is marked as detached, the MS is detached. In this state, the 
network may answer to a GPRS attach or combined GPRS attach procedure initiated by the MS. 
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4.1.3.3.1.2 



GMM-COMMON-PROCEDURE-INITIATED 



A common GMM procedure, as defined in subclause 4.1.1, has been started. The network is awaiting the answer from 
the MS. 

4.1.3.3.1.3 GMM-REGISTERED 

The GMM context has been established and the GPRS attach procedure has been successfully performed. 

4.1 .3.3.1 .4 GMM-DEREGISTERED-INITIATED 

The network has started a GPRS detach procedure and is awaiting the answer from the MS. 
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Figure 4.1c/3GPP TS 24.008: GMM main states on the networit side 

4.1 .3.3.2 Substates of state GMM-REGISTERED 

The state GMM-REGISTERED is subdivided into two substates as explained below. 

4.1 .3.3.2.1 GMM-REGISTERED.NORMAL-SERVIGE 
User data and signalling information may be sent and received. 

4.1 .3.3.2.2 GMM-REGISTERED. SUSPENDED (A/Gb mode only) 

In this substate, the lower layers shall be prevented of sending user data or signalling information. 
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4.2 Behaviour of the MS in IVIIVI Idle state, GMM- 

DEREGISTERED state and GMM-REGISTERED state 

In this subclause, the detailed behaviour of the MS in the main states MM IDLE, GMM-DEREGISTERED and GMM- 
REGISTERED is described. Subclauses 4.2.1 to 4.2.3 refer to the state MM IDLE, whereas subclauses 4.2.4 and 4.2.5 
refer to the states GMM-DEREGISTERED and GMM-REGISTERED, respectively. 

The MM IDLE state is entered when none of the MM procedures are running and no RR connection exists. It is left 
when one of the MM procedures are triggered or a RR connection is established. 

The specific behaviour in the MM IDLE state depends on the service state of the mobile station as described in 
subclause 4.1.2.1.2. The service state depends in particular on the update status which is defined in subclause 4.1.2.2. 

How an appropriate service state is chosen after power on is described in subclause 4.2.1, and the specific behaviour of 
the mobile station in MM IDLE state is described in subclause 4.2.2. The service state chosen when the MM IDLE state 
is returned to from any state except NULL state is described in subclause 4.2.3. 

It should be noted that transitions between the various MM idle states are caused by (e.g.): 

results of procedures on RR connected mode (see subclause 4.2.3); 

insertion or removal of the SIM/USIM; 

- cell selection/reselection (see also 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]); 

- PLMN search; 

loss of coverage. 

How various MM procedures affects the service state and the update status is described in the detailed descriptions of 
the procedures in subclauses 4.3 to 4.5. 

4.2.1 Primary Service State selection 

4.2.1 .1 Selection of the Service State after Power On. 

For an eCall only mobile station (as determined by information configured in the USIM), Timers T3242 and T3243 are 
considered to have expired at power-on. When mobility management is activated after power-on, the service state is 
19.7 PLMN SEARCH. The detailed processing in this state is described in detail in 3GPP TS 23.122 [14], 
3GPP TS 43.022 [82], 3GPP TS 45.008 [34] and 3GPP TS 25.304 [98], where procedures for power on and selection of 
PLMN is described in detail. If the "Location update status" stored on the SIM/USIM is different from "updated", then 
the mobile shall act as if the "Location update status" stored on the SIM/USIM is "not updated". 

The service state when the PLMN SEARCH state is left depends on the outcome of the search and on the presence of 
the SIM/USIM: 

if no cell has been found, the state is NO CELL AVAILABLE, until a cell is found; 

- if no SIM/USIM is present the state is NO IMSI; 

for an eCall only mobile station (as determined by information configured in USIM), the state is eCALL 
INACTIVE. 

if the mobile station has been continuously activated since loosing coverage and then returns to coverage, and if 
the selected cell is in the location area where the mobile station is registered and the timer T3212 has not 
expired, then the state is NORMAL SERVICE; 

if the selected cell is in the location area where the mobile station is registered and IMSI ATTACH is not 
required and timer T3212 has not expired, then the state is NORMAL SERVICE; 

if the mobile station is in automatic network selection mode and the selected cell is in a forbidden PLMN, is in a 
forbidden LA, or is a CSG cell whose CSG ID and associated PLMN identity are not in the Allowed CSG list or 
in the Operator CSG list stored in the MS, then the mobile station enters the LIMITED SERVICE state; 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 1 64 ETSI TS 1 24 008 V1 0.1 0.0 (201 3-04) 

if the mobile station is in manual network selection mode and no cell of the selected PLMN has been found, or 
the cell that is found in the selected PLMN is a CSG cell whose CSG ID and associated PLMN identity are not 
in the Allowed CSG list or in the Operator CSG list stored in the MS, then the mobile station enters the 
LIMITED SERVICE state; 

- otherwise, the mobile station enters the LOCATION UPDATE NEEDED state. 

4.2.1.2 Other Cases 

The state PLMN SEARCH is also entered in the following cases: 

- in state NO IMSI, a SIM/USIM is inserted; 

- in any state except NO IMSI, NO CELL AVAILABLE, NORMAL SERVICE and RECEIVING GROUP CALL 
(NORMAL SERVICE) after the user has asked for a PLMN selection; 

- in any state except NO IMSI and NO CELL AVAILABLE, coverage is lost; 

roaming is denied; 

optionally, when the mobile station is in the ATTEMPTING TO UPDATE state and is in Automatic Network 
Selection mode and location update attempt counter is greater than or equal to 4. 

The service state when the PLMN SEARCH is left depends on the outcome of the search and on the presence of the 
SIM/USIM as specified in subclause 4.2.1.1. 

4.2.2 Detailed Description of tine MS behaviour in MM IDLE State. 

In the MM IDLE state the mobile station shall behave according to the service state. In the following subclauses the 
behaviour is described for the non transient service states. It should be noted that after procedures in RR connected 
mode, e.g. location updating procedures, subclause 4.2.3 applies which specifies the selection of the MM idle state. 
Furthermore when in sub-state NORMAL SERVICE, if a PLMN selection is requested, the MS enters sub-state 
SEARCH FOR PLMN, NORMAL SERVICE. 

4.2.2.1 Service State, NORMAL SERVICE 

When in state MM IDLE and service state NORMAL SERVICE, the mobile station shall: 

provided that T3246 is not running, perform normal location updating when a new location area is entered; 

perform location updating procedure at expiry of timer T321 1 or T3213; 

perform periodic updating at expiration of timer T32 12; 

perform IMSI detach; 

provided that T3246 is not running, support requests from the CM layer; 

support request for emergency calls; 

respond to paging; and 

for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity 
procedure at expiry of timer T3242 or timer T3243. 

In addition, mobile stations supporting VGCS listening or VBS listening shall: 

indicate notifications to the GCC or BCC sublayer; 

respond to notification if the GCC or BCC sublayer requests the reception of a voice group or broadcast call for 
which no channel description has been received in the notification by the RR sublayer; 

request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the 
reception of a voice group or broadcast call for which a channel description has been received in the notification 
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (NORMAL SERVICE). 
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4.2.2.2 Service State, ATTEMPTING TO UPDATE 

When in state MM IDLE and service state ATTEMPTING TO UPDATE the mobile station shall: 

perform location updating procedure at expiry of timer T3211, T3213 or T3246; 

perform normal location updating when the location area identification of the serving cell changes, if timer 
T3246 is not running; 

if entry into this state was caused by c) or d) or f) (with cause different from "abnormal release, unspecified") or 
g) (with cause "retry upon entry into a new cell") of subclause 4.4.4.9, then location updating shall be performed 
when a new cell is entered; 

if entry into this state was caused by e) or f) (with cause "abnormal release, unspecified"), g) (with cause 
different from "retry upon entry into a new cell"), i) or j) of subclause 4.4.4.9, then location updating shall not be 
performed because a new cell is entered; 

perform normal location updating at expiry of timer T3212; 

not perform IMSI detach; 

support request for emergency calls; 

use other request from CM layer as triggering of normal location updating procedure (if the location updating 
procedure is successful, then the request for MM connection is accepted, see subclause 4.5. 1), if timer T3246 is 
not running; 

respond to paging (with IMSI) ; and 

for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity 
procedure at expiry of timer T3242 or timer T3243. 

In addition, mobile stations supporting VGCS listening or VBS listening shall: 

indicate notifications to the GCC or BCC sublayer for which a channel description has been received in the 
notification by the RR sublayer; 

reject requests of the GCC or BCC sublayer to respond to notifications for which no channel description has 
been received in the notification by the RR sublayer; 

request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the 
reception of a voice group or broadcast call for which a channel description has been received in the notification 
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (LIMITED SERVICE). 

4.2.2.3 Service State, LIMITED SERVICE 

When in state MM IDLE and service state LIMITED SERVICE the mobile station shall: 

not perform periodic updating; 

not perform IMSI detach; 

reject any requests from CM entities for MM connections except for emergency calls; 

perform normal location updating when a cell is entered which may provide normal service (e.g. location area 
not in one of the forbidden LAI lists.); 

it may respond to paging (with IMSI) ; and 

for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity 
procedure at expiry of timer T3242 or timer T3243. 

In addition, mobile stations supporting VGCS listening or VBS listening shall: 

indicate notifications to the GCC or BCC sublayer for which a channel description has been received in the 
notification by the RR sublayer; 
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reject requests of the GCC or BCC sublayer to respond to notifications for which no channel description has 
been received in the notification by the RR sublayer; 

request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the 
reception of a voice group or broadcast call for which a channel description has been received in the notification 
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (LIMITED SERVICE). 

4.2.2.4 Service State, NO IMSI 

When in state MM IDLE and service state NO IMSI the mobile station shall (see subclause 3.2, 3GPP TS 43.022 [82] 
and 3GPP TS 45.008 [34]): 

not start any normal location updating attempt; 

not perform periodic updating; 

not perform IMSI detach if powered down; 

reject any request from CM entities for MM connections except for emergency calls; 

not respond to paging; 

only perform default cell selection. 

In addition, mobile stations supporting VGCS listening or VBS Ustening shall: 

- not indicate notifications to the GCC or BCC layer. 

4.2.2.5 Service State, SEARCH FOR PLMN, NORMAL SERVICE 

When in state MM IDLE and service state SEARCH FOR PLMN, NORMAL SERVICE the mobile station shall: 

if timer T321 1 or T3213 expires in this state perform a location updating procedure at the latest if and when back 
to NORMAL SERVICE state and if the cell is not changed; 

if timer T3212 expires in this state perform a periodic location updating procedure at the latest if and when back 
to NORMAL SERVICE state; 

perform IMSI detach; 

support requests from the CM layer; 

listen as far as possible to paging, and respond; and 

for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity 
procedure at expiry of timer T3242 or T3243. 

In addition, mobile stations supporting VGCS listening or VBS listening shall: 

listen as far as possible to notifications and indicate notifications to the GCC or BCC layer; 

respond to notification if the GCC or BCC sublayer requests the reception of a voice group or broadcast call for 
which no channel description has been received in the notification by the RR sublayer; 

request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the 
reception of a voice group or broadcast call for which a channel description has been received in the notification 
by the RR sublayer. 

4.2.2.6 Service State, SEARCH FOR PLMN 

When in state MM IDLE and service state SEARCH FOR PLMN the mobile station shall: 
not start any normal location updating attempt; 
not perform periodic updating; 
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not perform IMSI detach if powered down; 

reject any request from CM entities for MM connections except emergency calls; 

not respond to paging. 

4.2.2.7 Service State, RECEIVING GROUP GALL (NORMAL SERVICE) 

Only applicable for mobile stations supporting VGCS listening or VBS listening: 

When in state MM IDLE and service state RECEIVING GROUP CALL (NORMAL SERVICE), the mobile station 
shall: 

perform normal location updating when a new location area is entered; 

perform location updating procedure at expiry of timer T321 1 or T3213; 

perform periodic updating at expiration of timer T3212; 

perform IMSI detach; 

support requests from the GCC or BCC layers; 

indicate notifications or paging information to the GCC or BCC layer; 

respond to notification if the GCC or BCC sublayer requests the reception of a voice group or broadcast call for 
which no channel description has been received in the notification by the RR sublayer; 

request the RR sublayer to receive another voice group or broadcast call if the GCC or BCC sublayer requests 
the reception of a voice group or broadcast call for which a channel description has been received in the 
notification by the RR sublayer. 

4.2.2.8 Service State, RECEIVING GROUP CALL (LIMITED SERVICE) 

Only applicable for mobile stations supporting VGCS listening or VBS listening: 

When in state MM IDLE and service state RECEIVING GROUP CALL (LIMITED SERVICE), the mobile station 
shall: 

not perform periodic updating; 

not perform IMSI detach; 

reject any requests from CM entities for MM connections except for emergency calls; 

perform normal location updating when a cell is entered which may provide normal service (e.g. location area 
not in one of the forbidden LAI lists.); 

it may respond to paging (with IMSI); 

indicate notifications to the GCC or BCC sublayer for which a channel description has been received in the 
notification by the RR sublayer; 

reject requests of the GCC or BCC sublayer to respond to notifications for which no channel description has 
been received in the notification by the RR sublayer; 

request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the 
reception of a voice group or broadcast call for which a channel description has been received in the notification 
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (LIMITED SERVICE). 

4.2.2.9 Service State, eCALL INACTIVE 

When in state MM IDLE and service state eCALL INACTIVE, the mobile station shall: 
not perform periodic updating; 
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not perform IMSI detach; 

reject any requests from CM entities for MM connections except for emergency calls and calls to a non- 
emergency MSISDN for test and terminal reconfiguration services; 

not perform normal location updating; and 

not respond to paging. 

4.2.3 Service state when back to state MM IDLE from another state 

When returning to MM IDLE, e.g., after a location updating procedure, the mobile station selects the cell as specified in 
3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. With one exception, this is a normal cell selection. 

An eCall only mobile station (as determined by information configured in USIM), shall start timer T3242 if the return 
to MM IDLE state is the result of an emergency services call and shall start timer T3243 if the return to MM IDLE state 
is the result of a call to a non-emergency MSISDN for test and terminal reconfiguration services, as described in 
subclause 4.4.7. 

If this return to idle state is not subsequent to a location updating procedure terminated with reception of cause 
"Roaming not allowed in this location area", the service state depends on the result of the cell selection procedure, on 
the update status of the mobile station, on the location data stored in the mobile station and on the presence of the 
SIM/USIM: 

if no cell has been found, the state is NO CELL AVAILABLE, until a cell is found; 

- if no SIM/USIM is present, or if the inserted SIM/USIM is considered invalid by the MS, the state is NO IMSI; 

for an eCall only mobile station (as determined by information configured in USIM), if timer T3242 or timer 
T3243 has expired and service state PLMN SEARCH is not required, the state is eCALL INACTIVE and the 
eCall inactivity procedure is performed as described in subclause 4.4.7; 

if the selected cell is in the location area where the MS is registered, then the state is NORMAL SERVICE; it 
shall be noted that this also includes an abnormal case described in subclause 4.4.4.9; 

(Only applicable for mobile stations supporting VGCS listening or VBS listening.) if the mobile stations was in 
the service state RECEIVING GROUP CALL (NORMAL SERVICE) or RECEIVING GROUP CALL 
(LIMITED SERVICE) before the location updating procedure and the selected cell is in the location area where 
the mobile station is registered, then the state is RECEIVING GROUP CALL (NORMAL SERVICE); 

if the selected cell is in a location area where the mobile station is not registered but in which the MS is allowed 
to attempt a location update, then the state is LOCATION UPDATE NEEDED; 

if the selected cell is in a location area where the mobile station is not allowed to attempt a location update, then 
the state is LIMITED SERVICE; 

if the selected cell is a CSG cell whose CSG ID and associated PLMN identity are not in the Allowed CSG list 
or in the Operator CSG list stored in the MS, then the state is LIMITED SERVICE; 

(Only applicable for MSs supporting VGCS listening or VBS listening.) if the MSs was in the service state 
RECEIVING GROUP CALL (NORMAL SERVICE) or RECEIVING GROUP CALL (LIMITED SERVICE) 
before the location updating procedure and the selected cell is in the location area where the MS is not allowed 
to attempt a location update, then the state is RECEIVING GROUP CALL (LIMITED SERVICE); 

after some abnormal cases occurring during an unsuccessful location updating procedure, as described in 
subclause 4.4.4.9, the state is ATTEMPTING TO UPDATE. 

In case of a return from a location updating procedure to which was answered "Roaming not allowed in this location 
area", the service state PLMN SEARCH is entered as specified in subclause 4.2.1.2. 

4.2.4 Behaviour in state GMM-DEREGISTERED 

The state GMM-DEREGISTERED is entered when: 
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the MS is switched on; 

the GPRS capability has been enabled in the MS; 

a GPRS detach or combined GPRS detach procedure has been performed; or 

a GMM procedure has failed (except routing area updating, see subclause 4.7.5). 

The selection of the appropriate substate of GMM-DEREGISTERED after switching on is described in 
subclause 4.2.4.1. The specific behaviour of the MS in state GMM-DEREGISTERED is described in subclause 4.2.4.2. 
The substate chosen when the GMM-DEREGISTERED state is returned to from another state except state GMM- 
NULL is described in subclause 4.2.4.3. 

It should be noted that transitions between the various substates of GMM-DEREGISTERED are caused by (e.g.): 

insertion or removal of the SIM/USIM; 

- cell selection/reselection (see also 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]); 

- PLMN search; 
loss/regain of coverage; or 

- change of RA. 

How various GMM procedures affect the GMM-DEREGISTERED substates and the GPRS update status is described 
in the detailed description of the GMM procedures in subclause 4.7. 

4.2.4.1 Primary substate selection 

4.2.4.1 .1 Selection of the substate after power on or enabling the MS's GPRS capability 

When the MS is switched on, the substate shall be PLMN-SEARCH in case the SIM/USIM is inserted and vaUd. See 
3GPP TS 23.122 [14] and 3GPP TS 45.008 [34] for further details. 

When the GPRS capability in an activated MS has been enabled, the selection of the GMM-DEREGISTERED substate 
depends on the MM state and the GPRS update status. 

The substate chosen after PLMN-SEARCH, in case of power on or after enabling of the GPRS capability is: 

- if the cell is not supporting GPRS, the substate shall be NO-CELL- AVAILABLE; 

- if no SIM/USIM is present the substate shall be NO-IMSI; 

if a suitable cell supporting GPRS has been found and the PLMN or LA is not in the forbidden list, then the 
substate shall be NORMAL-SERVICE; 

if the selected cell supporting GPRS is in a forbidden PLMN, is in a forbidden LA, or is a CSG cell with a CSG 
ID and associated PLMN identity that are not in Allowed CSG list or in the Operator CSG list stored in the MS , 
then the MS shall enter the substate LIMITED-SERVICE; 

if the MS is in manual network selection mode and no cell supporting GPRS of the selected PLMN has been 
found, the MS shall enter the substate NO-CELL- AVAILABLE. 

4.2.4.1.2 Other Cases 

When the MM state is IDLE, the GMM substate PLMN-SEARCH shall also be entered in the following cases: 

- when a SIM/USIM is inserted in substate NO-IMSI; 

- when the user has asked for a PLMN selection in any substate except NO IMSI and NO CELL AVAILABLE ; 

- when coverage is lost in any substate except NO IMSI and NO CELL AVAILABLE ; 
Roaming is denied; 
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optionally, when the MS is in automatic network selection mode and the maximum allowed number of 
subsequently unsuccessful attach attempts controlled by the GPRS attach attempt counter (subclause 4.7.3) have 
been performed. 

4.2.4.2 Detailed description of the MS behaviour in state GMM-DEREGISTERED 

In state GMM-DEREGISTERED, the MS shall behave according to the substate. In the following subclauses, the 
behaviour is described for the non transient substates. 

4.2.4.2.1 Substate, NORMAL-SERVICE 
The MS shall: 

- initiate GPRS attach. 

4.2.4.2.2 Substate, ATTEMPTING-TO-ATTACH 
The MS: 

- shall initiate GPRS attach on the expiry of timers T33 1 1 , T3302, or T3346; 

shall initiate GPRS attach when entering a new PLMN not in the list of equivalent PLMNs, if the PLMN identity 
of the new cell is not in one of the forbidden PLMN lists and the location area this cell is belonging to is not in 
one of the lists of forbidden LAs; 

may initiate GPRS attach for emergency bearer services (UTRAN lu mode only) even if timer T3346 is running; 

shall initiate GPRS attach when the routing area of the serving cell in the current PLMN or equivalent PLMN 
has changed, if timer T3346 is not running and the location area this cell is belonging to is not in one of the lists 
of forbidden LAs; 

shall if entry into this state was caused by b) or d) with cause "Retry upon entry into a new cell" of 
subclause 4.7.3. L5, perform GPRS attach when a new cell is entered; 

shall if entry into this state was caused by c) or d) with cause different from "Retry upon entry into a new cell" of 
subclause 4.7.3.1.5, not perform GPRS attach when a new cell is entered; 

shall use requests from CM layers to trigger the combined GPRS attach procedure, if the network operates in 
network operation mode I. Depending on which of the timers T3311 or T3302 is running the MS shall stop the 
relevant timer and act as if the stopped timer has expired; and 

- shall initiate GPRS attach upon request of the upper layers to establish a PDN connection for emergency bearer 
services (UTRAN lu mode only). 

4.2.4.2.3 Substate, LIMITED-SERVICE 

The MS: 

shall initiate GPRS attach when a cell is entered which may provide normal service (e.g. location area is not in 
one of the forbidden lists); and 

may initiate GPRS attach for emergency bearer services (UTRAN lu mode only). 

4.2.4.2.4 Substate, NO-IMSI 
The MS: 

shall perform default cell selection; and 

may initiate GPRS attach for emergency bearer services (UTRAN lu mode only). 
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4.2.4.2.5 Substate, NO-CELL 
The MS shall: 

- perform cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] and shall choose an 
appropriate substate. 

4.2.4.2.6 Substate, PLMN-SEARCH 

The MS shall perform PLMN selection. If a new PLMN is selected, the MS shall reset the GPRS attach attempt counter 
and initiate the GPRS attach procedure (see subclause 4.7.3.1). 

4.2.4.2.7 Substate, ATTACH-NEEDED 

The MS shall start a GPRS attach procedure if still needed as soon as the access class control allows network contact in 
the selected cell. 

4.2.4.2.8 Substate, SUSPENDED (A/Gb mode only) 
The MS: 

shall not send any user data; and 

shall not send any signalling information. 

4.2.4.3 Substate when back to state GMM-DEREGISTERED from another GMM 

state 

When returning to state GMM-DEREGISTERED, the MS shall select a cell as specified in 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

The substate depends on the result of the cell selection procedure, the outcome of the previously performed GMM 
specific procedures, on the GPRS update status of the MS, on the location area data stored in the MS and on the 
presence of the SIM/USIM: 

if no cell has been found, the substate is NO-CELL- AVAILABLE, until a cell is found; 

- if no SIM/USIM is present or if the inserted SIM/USIM is considered invalid by the MS, the substate shall be 
NO-IMSI; 

if a suitable cell supporting GPRS has been found and the PLMN or LA is not in the forbidden list, the substate 
shall be NORMAL-SERVICE; 

if a GPRS attach shall be performed (e.g. network requested reattach), the substate shall be ATTEMPTING-TO- 
ATTACH; 

- if a PLMN reselection (according to 3GPP TS 23.122 [14]) is needed, the substate shall be PLMN SEARCH; 

if the selected cell is known not to be able to provide normal service, the substate shall be LIMITED-SERVICE. 

4.2.5 Behaviour in state GMM-REGISTERED 

The state GMM-REGISTERED is entered when: 

- a GMM context is established, i.e. the MS is IMSI attached for GPRS services only or for GPRS and non-GPRS 

services. 

The specific behaviour of the MS in state GMM-REGISTERED is described in subclause 4.2.5.1. The primary substate 
when entering the state GMM-REGISTERED is always NORMAL-SERVICE. 

It should be noted that transitions between the various substates of GMM-REGISTERED are caused by (e.g.): 

- cell selection/reselection (see also 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]); 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 1 72 ETSI TS 1 24 008 V1 0.1 0.0 (201 3-04) 

- change of RA; 

loss/regain of coverage. 

How various GMM procedures affect the GMM -REGISTERED substates is described in the detailed description of the 
procedures in subclause 4.7. 

4.2.5.1 Detailed description of the MS behaviour in state GMM-REGISTERED 

In state GMM-REGISTERED, the MS shall behave according to the substate as explained below. 

4.2.5.1.1 Substate, NORMAL-SERVICE 
The MS shall: 

- perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]; 

initiate normal routing area updating; 

perform periodic routing area updating except when attached for emergency bearer services (see 
subclause 4.7.2.2); and 

receive and transmit user data and signalling information. 

GPRS MSs in operation modes C or A shall answer to paging requests. 

GPRS MS in operation mode B may answer to paging requests. 

4.2.5.1 .2 Substate, SUSPENDED (A/Gb mode only) 
The MS: 

shall not send any user data; 

shall not send any signalling information; and 

shall not perform cell-updates. 

4.2.5.1.3 Substate, UPDATE-NEEDED 

The MS shall: 

not send any user data; 

not send any signalling information; 

- perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]; and 

choose the appropriate new substate depending on the GPRS update status as soon as the access class control 
allows network contact in the selected cell. 

4.2.5.1.4 Substate, ATTEMPTING-TO-UPDATE 
The MS: 

should not send any user data; 

shall initiate routing area updating procedure on the expiry of timers T33 1 1 , T3302 or T3346; 

shall initiate routing area updating procedure when entering a new PLMN not in the list of equivalent PLMNs, if 
the PLMN identity of the new cell is not in one of the forbidden PLMN lists and the location area this cell is 
belonging to is not in one of the lists of forbidden LAs; 
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shall initiate routing area updating procedure when the routing area of the serving cell in the current PLMN or 
equivalent PLMN has changed, if timer T3346 is not running and the location area this cell is belonging to is not 
in one of the lists of forbidden LAs; 

shall, if entry into this state was caused by b) or d) with cause "Retry upon entry into a new cell" of 
subclause 4.7.5.1.5, initiate routing area updating procedure when a new cell is entered; 

shall, if entry into this state was caused by c) or d) with cause different from "Retry upon entry into a new cell" 
of subclause 4.7.5. 1 .5, not initiate routing area updating procedure when a new cell is entered; 

shall use request from CM layers to trigger the combined routing area updating procedure, if the network 
operates in network operation mode I. Depending on which of the timers T33 11 or T3302 is running the MS 
shall stop the relevant timer and act as if the stopped timer has expired; 

shall initiate routing area updating procedure upon request of the upper layers to establish a PDN connection for 
emergency bearer services (UTRAN lu mode only); and 

shall initiate routing area updating procedure in response to paging, if timer T3346 is running. 

4.2.5.1.5 Substate, NO-CELL-AVAILABLE 

The MS shall perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

4.2.5.1.6 Substate, LIMITED-SERVICE 
The MS: 

- shall perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] and 
may initiate GPRS attach for emergency bearer services (UTRAN lu mode only).; 

4.2.5.1.7 Substate, ATTEMPTING-TO-UPDATE-MM 
The MS shall: 

- perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]; 

receive and transmit user data and signalling information; 

initiate routing area update indicating "combined RA/LA updating with IMSI attach" on the expiry of timers 
T3311orT3302; 

initiate routing area update indicating "combined RA/LA updating with IMSI attach" when the routing area of 
the serving cell has changed and the location area this cell is belonging to is not in the list of forbidden LAs. 

GPRS MSs in operation modes C or A shall answer to paging requests. 

GPRS MS in operation mode B may answer to paging requests. 

4.2.5.1.8 Substate, PLMN-SEARCH 

When the MM state is IDLE, the GMM substate PLMN-SEARCH may be entered if the MS is in automatic network 
selection mode and the maximum allowed number of subsequently unsuccessful routing area update attempts controlled 
by the GPRS routing area updating attempt counter (subclause 4.7.5) have been performed. If a new PLMN is selected, 
the MS shall reset the routing area updating attempt counter and perform the routing area updating procedure. 



4.3 MM common procedures 



As described in subclause 4.1.1, a MM common procedure can be initiated at any time whilst a RR connection exists 
between the network and the mobile station. 
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4.3.1 TMSI reallocation procedure 



The purpose of the TMSI reallocation procedure is to provide identity confidentiality, i.e. to protect a user against being 
identified and located by an intruder (see 3GPP TS 42.009 [5], 3GPP TS 43.020 [13] and 3GPP TS 33.102 [5a]). 

If the identity confidentiality service is applied for an IMSI, a Temporary Mobile Subscriber Identity (TMSI) is used for 
identification within the radio interface signalling procedures. 

In a network supporting the feature 'Intra domain connection of RAN nodes to multiple CN nodes' a TMSI shall be 
allocated to each IMSI attached mobile station. See 3GPP TS 23.236 [94], subclause 4.3. 

The structure of the TMSI is specified in 3GPP TS 23.003 [10]. The TMSI has significance only within a location area. 
Outside the location area it has to be combined with the Location Area Identifier (LAI) to provide for an unambiguous 
identity. 

Usually the TMSI reallocation is performed at least at each change of a location area. (Such choices are left to the 
network operator). 

The reallocation of a TMSI can be performed either by a unique procedure defined in this subclause or implicitly by a 
location updating procedure using the TMSI. The implicit reallocation of a TMSI is described together with that 
procedure. 

If a TMSI provided by a mobile station is unknown in the network e.g. due to a data base failure, the network may 
require the mobile station to provide its International Mobile Subscriber Identity (IMSI). In this case the identification 
procedure (see subclause 4.3.3) should be used before the TMSI reallocation procedure may be initiated. 

The TMSI reallocation can be initiated by the network at any time whilst a RR connection exists between the network 
and the mobile station. 

NOTE 1 : Usually the TMSI reallocation is performed in ciphered mode. 

NOTE 2: Normally the TMSI reallocation will take place in conjunction with another procedure, e.g. at location 
updating or at call setup (see 3GPP TS 29.002 [37]). 

NOTE 3: The explicit TMSI reallocation procedure is started by the network only if the mobile station is updated in 
the current location area or if a location updating procedure is ongoing for that particular mobile station, 
or if the network wishes to send a non-broadcast LAI according to 3GPP TS 23.236 [94] to the mobile 
station. 

4.3.1 .1 TMSI reallocation initiation by the network 

The network initiates the TMSI reallocation procedure by sending a TMSI REALLOCATION COMMAND message to 
the mobile station and starts the timer T3250. 

The TMSI REALLOCATION COMMAND message contains a new combination of TMSI and LAI allocated by the 
network or a LAI and the IMSI if the used TMSI shall be deleted. Usually the TMSI-REALLOCATION COMMAND 
message is sent to the mobile station using a RR connection in ciphered mode (see 3GPP TS 43.020 [13] and 
3GPPTS 33.102 [5a]). 

4.3.1 .2 TMSI reallocation completion by the mobile station 

Upon receipt of the TMSI REALLOCATION COMMAND message the mobile station stores the Location Area 
Identifier (LAI) in the SIM/USIM. If the received identity is the IMSI of the relevant mobile station, the mobile station 
deletes any TMSI. If the received identity is a TMSI the mobile station stores the TMSI in the SIM/USIM. In both cases 
the mobile station sends a TMSI REALLOCATION COMPLETE message to the network. 

4.3.1 .3 TMSI reallocation completion in the network. 

Upon receipt of the TMSI REALLOCATION COMPLETE message, the network stops the timer T3250 and either 
considers the new TMSI as valid or, if an IMSI was sent to the mobile station, considers the old TMSI as deleted. 

If the RR connection is no more needed, then the network will request the RR sublayer to release it (see 
3GPP TS 44.018 [84] subclause 3.5 and 3GPP TS 25.331 [23c]). 
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4.3.1.4 Abnormal cases 

Mobile station side: 

The mobile station shall consider the new TMSI and new LAI, if any, as valid and the old TMSI and old LAI as 
deleted as soon as a TMSI REALLOCATION COMMAND or another message containing a new TMSI (e.g. 
LOCATION UPDATING ACCEPT) is correctly received. Any RR connection failure at a later stage shall not 
have any impact on the TMSI and LAI storage. 

Network side: 

(a) RR connection failure: 

If the RR connection is lost before the TMSI REALLOCATION COMPLETE message is received, all MM 
connections (if any) shall be released and both the old and the new TMSIs should be considered as occupied 
for a certain recovery time. 

During this period the network may: 

use the IMSI for paging in the case of network originated transactions on the CM layer. Upon response 
from the mobile station the TMSI reallocation is restarted; 

consider the new TMSI as valid if it is used by the mobile station in mobile originated requests for RR 
connection; 

use the Identification procedure followed by a new TMSI reallocation if the mobile station uses the old 
TMSI. 

Other implementations are possible. 

(b) Expiry of timer T3250: 

The TMSI reallocation is supervised by the timer T3250 in the network. At the first expiry of timer T3250 
the network may release the RR connection. In this case, the network shall abort the reallocation procedure 
release all MM connections if any, and follow the rules described for RR connection failure above. 

mobile station network 

TMSI REAL CMD 
< Start T3250 

TMSI REAL COM 

> stop T3250 

Figure 4.1/3GPP TS 24.008: TMSI reallocation sequence 

4.3.2 Authentication procedure 

4.3.2a Authentication procedure used for a UMTS authentication challenge 

The purpose of the authentication procedure is fourfold (see 3GPP TS 33.102 [5a]): 

First to permit the network to check whether the identity provided by the mobile station is acceptable or not; 

Second to provide parameters enabling the mobile station to calculate a new UMTS ciphering key; 

Third to provide parameters enabling the mobile station to calculate a new UMTS integrity key; 

Fourth to permit the mobile station to authenticate the network. 

The cases where the authentication procedure should be used are defined in 3GPP TS 33.102 [5a]. 

The UMTS authentication procedure is always initiated and controlled by the network. However, there is the possibiUty 
for the MS to reject the UMTS authentication challenge sent by the network. 
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The MS shall support the UMTS authentication challenge, if a USIM is inserted. 

A UMTS security context is established in the MS and the network when a UMTS authentication challenge is 
performed in A/Gb mode or in lu mode. After a successful UMTS authentication, the UMTS ciphering key, the UMTS 
integrity key, the GSM ciphering key and the ciphering key sequence number, are stored both in the network and the 
MS. Furthermore, in A/Gb mode both the ME and the network may derive and store a GSM Kc^g as part of the UMTS 
security context as described in the subclause 4.3.2.3a. 

4.3.2b Authentication Procedure used for a GSM authentication challenge 

The purpose of the authentication procedure is twofold (see 3GPP TS 43.020 [13]): 

First to permit the network to check whether the identity provided by the mobile station is acceptable or not; 

Second to provide parameters enabling the mobile station to calculate a new GSM ciphering key. 

The cases where the authentication procedure should be used are defined in 3GPP TS 42.009 [5]. 

The authentication procedure is always initiated and controlled by the network. GSM authentication challenge shall be 
supported by a ME supporting GERAN or UTRAN. 

A GSM security context is established in the MS and the network when a GSM authentication challenge is performed in 
A/Gb mode or in lu mode. However, in lu mode the MS shall not accept a GSM authentication challenge, if a USIM is 
inserted. After a successful GSM authentication, the GSM ciphering key and the ciphering key sequence number, are 
stored both in the network and the MS. 

4.3.2.1 Authentication request by the network 

The network initiates the authentication procedure by transferring an AUTHENTICATION REQUEST message across 
the radio interface and starts the timer T3260. The AUTHENTICATION REQUEST message contains the parameters 
necessary to calculate the response parameters (see 3GPP TS 43.020 [13] (in case of GSM authentication challenge) 
and 3GPP TS 33.102 [5a] (in case of an UMTS authentication challenge)). 

In a GSM authentication challenge, the AUTHENTICATION REQUEST message also contains the GSM ciphering key 
sequence number allocated to the key which may be computed from the given parameters. 

In a UMTS authentication challenge, the AUTHENTICATION REQUEST message also contains the ciphering key 
sequence number allocated to the key set of UMTS ciphering key, UMTS integrity key and GSM ciphering key which 
may be computed from the given parameters. Furthermore, the ciphering key sequence number is also linked to a GSM 
Kci28 if after the authentication procedure the network in A/Gb mode selects an A5 ciphering algorithm that requires a 
128-bit ciphering key. 

4.3.2.2 Authentication response by the mobile station 

The mobile station shall be ready to respond upon an AUTHENTICATION REQUEST message at any time whilst a 
RR connection exists. With exception of the cases described in subclause 4.3.2.5.1, it shall process the challenge 
information and send back an AUTHENTICATION RESPONSE message to the network. 

If a SIM is inserted in the MS, the MS shall ignore the Authentication Parameter AUTN IE if included in the 
AUTHENTICATION REQUEST message and shall proceed as in case of a GSM authentication challenge. It shall not 
perform the authentication of the network described in subclause 4.3.2.5. 1. 

In a GSM authentication challenge, the new GSM ciphering key calculated from the challenge information shall 
overwrite the previous GSM ciphering key and any previously stored UMTS ciphering key and UMTS integrity key 
shall be deleted. The new GSM ciphering key shall be stored on the SIM/USIM together with the ciphering key 
sequence number. 

In a UMTS authentication challenge, the new UMTS ciphering key, the new GSM ciphering key and the new UMTS 
integrity key calculated from the challenge information shall overwrite the previous UMTS ciphering key, GSM 
ciphering key and UMTS integrity key. The new UMTS ciphering key, GSM ciphering key and UMTS integrity key are 
stored on the USIM together with the ciphering key sequence number. Furthermore, in A/Gb mode when after the 
authentication procedure an A5 ciphering algorithm that requires a 128-bit ciphering key is taken into use, then a new 
GSM Kci28 shall also be calculated as described in the subclause 4.3.2.3a. 
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The SIM/USIM will provide the mobile station with the authentication response, based upon the authentication 
challenge given from the ME. A UMTS authentication challenge will result in the USIM passing a RES to the ME. A 
GSM authentication challenge will result in the SIM/USIM passing a SRES to the ME. 

A ME supporting UMTS authentication challenge may support the following procedure: 

In order to avoid a synchronisation failure, when the mobile station receives an AUTHENTICATION REQUEST 
message, the mobile station shall store the received RAND together with the RES returned from the USIM in the 
volatile memory and associate it with CS domain. When the MS receives a subsequent AUTHENTICATION 
REQUEST message, if the stored RAND value for the CS domain is equal to the new received value in the 
AUTHENTICATION REQUEST message, then the mobile station shall not pass the RAND to the USIM, but shall 
immediately send the AUTHENTICATION RESPONSE message with the stored RES for the CS domain. If, for the CS 
domain, there is no valid stored RAND in the mobile station or the stored RAND is different from the new received 
value in the AUTHENTICATION REQUEST message, the mobile station shall pass the RAND to the USIM, shall 
override any previously stored RAND and RES with the new ones and start, or reset and restart timer T3218. 

The RAND and RES values stored in the mobile station shall be deleted and timer T3218, if running, shall be stopped: 

- upon receipt of a SECURITY MODE COMMAND (lu mode only), 

CIPHERING MODE COMMAND (A/Gb mode only), 

CM_SERVICE_ACCEPT, 

CM_SERVICE_REJECT, 

LOCATION_UPDATING_ACCEPT 

or AUTHENTICATION REJECT message; 

upon expiry of timer T32 1 8 ; or 

- if the mobile station enters the MM state MM IDLE or NULL. 

4.3.2.3 Authentication processing in the network 

Upon receipt of the AUTHENTICATION RESPONSE message, the network stops the timer T3260 and checks the 
validity of the response (see 3GPP TS 43.020 [13] in case of a GSM authentication challenge respective 
3GPP TS 33.102 [5a] in case of an UMTS authentication challenge). 

Upon receipt of the AUTHENTICATION FAILURE message, the network stops the timer T3260. In Synch failure 
case, the core network may renegotiate with the HLR/AuC and provide the MS with new authentication parameters. 

4.3.2.3a 1 28-bit circuit-switched GSM ciphering key 

The ME and the network may derive and store a 128-bit circuit-switched GSM ciphering key or GSM Kc^g from an 
established UMTS security context. If the GSM Kci28 exists, then it is also part of the UMTS security context. 

The ME with a USIM in use shall compute a new GSM Kci28 using the UMTS ciphering key and the UMTS integrity 
key from an established UMTS security context as specified in 3GPP TS 33.102 [5a]. The new GSM Kci28 shall be 
stored only in the ME. The ME shall overwrite the existing GSM Kci28 with the new GSM Kci28. The ME shall delete 
the GSM Kci28 at switch off, when the USIM is disabled as well as under the conditions identified in the 
subclause 4.1.2.2 and 4.3.2.4. The ME with a USIM in use shall apply the GSM Kci28 when in A/Gb mode an A5 
ciphering algorithm that requires a 128-bit ciphering key is taken into use. 

The network shall compute the GSM Kci28 using the UMTS integrity key and the UMTS ciphering key from an 
established UMTS security context as specified in 3GPP TS 33.102 [5a] only when in A/Gb mode an A5 ciphering 
algorithm that requires a 128-bit ciphering key is to be used. 

4.3.2.4 Ciphering key sequence number 

The security parameters for authentication and ciphering are tied together in sets. 

In a GSM authentication challenge, from a challenge parameter RAND both the authentication response parameter 
SRES and the GSM ciphering key can be computed given the secret key associated to the IMS! 

In a UMTS authentication challenge, from a challenge parameter RAND, the authentication response parameter RES 
and the UMTS ciphering key and the UMTS integrity key can be computed given the secret key associated to the IMSI. 
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In addition, in the USIM a GSM ciphering key can be computed from the UMTS ciphering key and the UMTS integrity 
key by means of an unkeyed conversion function. Furthermore, in A/Gb mode if an A5 ciphering algorithm that 
requires a 128-bit ciphering key is taken into use, then a GSM Kc^g shall also be calculated as described in the 
subclause 4.3.2.3a. 

In order to allow start of ciphering on a RR connection without authentication, the ciphering key sequence numbers are 
introduced. The ciphering key sequence number is managed by the network in the way that the AUTHENTICATION 
REQUEST message contains the ciphering key sequence number allocated to the GSM ciphering key (in case of a GSM 
authentication challenge) or the UMTS ciphering key and the UMTS integrity key (in case of a UMTS authentication 
challenge) which may be computed from the RAND parameter carried in that message. 

If an authentication procedure has been completed successfully and a ciphering key sequence number is stored in the 
network, the network shall include a different ciphering key sequence number in the AUTHENTICATION REQUEST 
message when it intiates a new authentication procedure. 

The mobile station stores the ciphering key sequence number with the GSM ciphering key (in case of a GSM 
authentication challenge) and the UMTS ciphering key and the UMTS integrity key (in case of a UMTS authentication 
challenge) and indicates to the network in the first message (LOCATION UPDATING REQUEST, CM SERVICE 
REQUEST, PAGING RESPONSE, CM RE-ESTABLISHMENT REQUEST) which ciphering key sequence number 
the stored GSM ciphering key (in case of a GSM authentication challenge) or set of UMTS ciphering, UMTS integrity, 
derived GSM ciphering key, and potentially the derived GSM Kci28 (in case of a UMTS authentication challenge) has. 

When the deletion of the ciphering key sequence number is described this also means that the associated GSM 
ciphering key, the UMTS ciphering key and the UMTS integrity key shall be considered as invalid and also the GSM 
Kci28 shall be deleted if any (i.e. the established GSM security context or the UMTS security context is no longer valid). 

In A/Gb mode, the network may choose to start ciphering with the stored GSM ciphering key or GSM KC|28 (under the 
restrictions given in 3GPP TS 42.009 [5]) if the stored ciphering key sequence number and the one given from the 
mobile station are equal. 

NOTE I: The decision of starting ciphering with the GSM ciphering key or the GSM Kci28 depends on whether the 
network indicates in the CIPHERING MODE COMMAND message an A5 ciphering algorithm which 
requires a 64 or 128-bit ciphering key as specified in 3GPP TS 33.102 [5a]. 

In lu mode, the network may choose to start ciphering and integrity with the stored UMTS ciphering key and UMTS 
integrity key (under the restrictions given in 3GPP TS 42.009 [5] and 3GPP TS 33.102 [5a]) if the stored ciphering key 
sequence number and the one given from the mobile station are equal. 

NOTE 2: In some specifications the term KSI (Key Set Identifier) might be used instead of the term ciphering key 
sequence number. 

4.3.2.5 Authentication not accepted by the network 

If authentication fails, i.e. if the response is not valid, the network may distinguish between the two different ways of 
identification used by the mobile station: 

- the TMSI was used; 

- the IMSI was used. 

If the TMSI has been used, the network may decide to initiate the identification procedure. If the IMSI given by the 
mobile station then differs from the one the network had associated with the TMSI, the authentication should be 
restarted with the correct parameters. If the IMSI provided by the MS is the expected one (i.e. authentication has really 
failed), the network should proceed as described below. 

If the IMSI has been used, or the network decides not to try the identification procedure, an AUTHENTICATION 
REJECT message should be transferred to the mobile station. 

After having sent this message, all MM connections in progress (if any) are released and the network should initiate the 
RR connection release procedure described in subclause 3. 5. of 3GPP TS 44.018 [84] (A/Gb mode only), 
3GPP TS 25.331 [23c] (UTRAN lu mode only), or in 3GPP TS 44.118 [111] (GERAN lu mode only). 
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Upon receipt of an AUTHENTICATION REJECT message, the mobile station shall set the update status in the 
SIM/USIM to U3 ROAMING NOT ALLOWED, delete from the SIM/USIM the stored TMSI, LAI and ciphering key 
sequence number. The SIM/USIM shall be considered as invalid until switching off or the SIM/USIM is removed. 

If the AUTHENTICATION REJECT message is received in the state IMSI DETACH INITIATED the mobile station 
shall follow subclause 4.3.4.3. 

If the AUTHENTICATION REJECT message is received in any other state the mobile station shall abort any MM 
specific, MM connection establishment or call re-establishment procedure, stop any of the timers T3210 or T3230 (if 
running), release all MM connections (if any), start timer T3240 and enter the state WAIT FOR NETWORK 
COMMAND, expecting the release of the RR connection. If the RR connection is not released within a given time 
controlled by the timer T3240, the mobile station shall abort the RR connection. In both cases, either after a RR 
connection release triggered from the network side or after a RR connection abort requested by the MS -side, the MS 
enters state MM IDLE, substate NO IMSI. 

4.3.2.5.1 Authentication not accepted by the MS 

In a UMTS authentication challenge, the authentication procedure is extended to allow the MS to check the authenticity 
of the core network. Thus allowing, for instance, detection of false base station. 

Following a UMTS authentication challenge, the MS may reject the core network, on the grounds of an incorrect 
AUTN parameter (see 3GPP TS 33.102 [5a]). This parameter contains two possible causes for authentication failure: 

a) MAC code failure: 

If the MS considers the MAC code (supplied by the core network in the AUTN parameter) to be invalid, it 
shall send an AUTHENTICATION FAILURE message to the network, with the reject cause 'MAC failure'. 
The MS shall then follow the procedure described in subclause 4.3.2.6 (c). 

b) SQN failure: 

If the MS considers the SQN (supplied by the core network in the AUTN parameter) to be out of range, it 
shall send a AUTHENTICATION FAILURE message to the network, with the reject cause 'Synch failure' 
and a re-synchronization token AUTS provided by the USIM (see 3GPP TS 33.102 [5a]). The MS shall then 
follow the procedure described in subclause 4.3.2.6 (d). 

In UMTS, an MS with a USIM inserted shall reject the authentication challenge if no Authentication Parameter AUTN 
IE was present in the AUTHENTICATION REQUEST message (i.e. a GSM authentication challenge has been received 
when the MS expects a UMTS authentication challenge). In such a case, the MS shall send the AUTHENTICATION 
FAILURE message to the network, with the reject cause "GSM authentication unacceptable". The MS shall then follow 
the procedure described in subclause 4.3.2.6 (c). 

If the MS returns an AUTHENTICATION_FAILURE message to the network, the MS shall delete any previously 
stored RAND and RES and shall stop timer T3218, if running. 

4.3.2.6 Abnormal cases 

(a) RR connection failure: 

Upon detection of a RR connection failure before the AUTHENTICATION RESPONSE is received, the 
network shall release all MM connections (if any) and abort any ongoing MM specific procedure. 

(b) Expiry of timer T3260: 

The authentication procedure is supervised on the network side by the timer T3260. At expiry of this timer the 
network may release the RR connection. In this case the network shall abort the authentication procedure and 
any ongoing MM specific procedure, release all MM connections if any, and initiate the RR connection release 
procedure described in subclause 3.5 of 3GPP TS 44.018 [84] (A/Gb mode only), 3GPP TS 25.331 [23c] 
(UTRAN lu mode only), or in 3GPP TS 44. 118 [111] (GERAN lu mode only). 

(c) Authentication failure (reject cause "MAC failure" or "GSM authentication unacceptable"): 

The MS shall send an AUTHENTICATION FAILURE message, with reject cause "MAC failure" or "GSM 
authentication unacceptable" according to subclause 4.3.2.5.1, to the network and start timer T3214. 
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Furthermore, the MS shall stop any of the retransmission timers that are running (e.g. T3210, T3220 or T3230). 
Upon the first receipt of an AUTHENTICATION FAILURE message from the MS with reject cause "MAC 
failure" or "GSM authentication unacceptable", the network may initiate the identification procedure described 
in subclause 4.3.3. This is to allow the network to obtain the IMSI from the MS. The network may then check 
that the TMSI originally used in the authentication challenge corresponded to the correct IMSI. Upon receipt of 
the IDENTITY REQUEST message from the network, the MS shall send the IDENTITY RESPONSE message. 

NOTE: Upon receipt of an AUTHENTICATION FAILURE message from the MS with reject cause "MAC 
failure" or "GSM authentication unacceptable", the network may also terminate the authentication 
procedure (see subclause 4.3.2.5). 

If the TMSI/IMSI mapping in the network was incorrect, the network should respond by sending a new 
AUTHENTICATION REQUEST message to the MS. Upon receiving the new AUTHENTICATION REQUEST 
message from the network, the MS shall stop the timer T3214, if running, and then process the challenge 
information as normal. 

If the network is validated successfully (an AUTHENTICATION REQUEST that contains a valid SQN and 
MAC is received), the MS shall send the AUTHENTICATION RESPONSE message to the network and shall 
start any retransmission timers (e.g. T3210, T3220 or T3230), if they were running and stopped when the MS 
received the first failed AUTHENTICATION REQUEST message. 

If the MS receives the second AUTHENTICATION REQUEST while T3214 is running, and the MAC value 
cannot be resolved or the message contains a GSM authentication challenge, the MS shall follow the procedure 
specified in this subclause (c), starting again from the beginning. If the SQN is invalid, the MS shall proceed as 
specified in (d). 

It can be assumed that the source of the authentication challenge is not genuine (authentication not accepted by 
the MS) if any of the following occur: 

- after sending the AUTHENTICATION FAILURE message with the reject cause "MAC failure" or "GSM 
authentication unacceptable" the timer T3214 expires; 

- the MS detects any combination of the authentication failures: "MAC failure", "invahd SQN", and "GSM 
authentication unacceptable", during three consecutive authentication challenges. The authentication 
challenges shall be considered as consecutive only, if the authentication challenges causing the second and 
third authentication failure are received by the MS, while the timer T3214 or T3216 started after the previous 
authentication failure is running. 

When it has been deemed by the MS that the source of the authentication challenge is not genuine (i.e. 
authentication not accepted by the MS), the MS shall behave as described in subclause 4.3.2.6. L 
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Figure 4.2/3GPP TS 24.008: Authentication Failure Procedure 
(reject cause "MAC failure" or "GSM authentication unacceptable") 

(d) Authentication failure (reject cause "synch failure"): 

The MS shall send an AUTHENTICATION FAILURE message, with reject cause "synch failure", to the 
network and start the timer T3216. Furthermore, the MS shall stop any of the retransmission timers that are 
running (e.g. T3210, T3220 or T3230). Upon the first receipt of an AUTHENTICATION FAILURE message 
from the MS with the reject cause "synch failure", the network shall use the returned AUTS parameter from the 
authentication failure parameter IE in the AUTHENTICATION FAILURE message, to re-synchronise. The re- 
synchronisation procedure requires the VLR/MSC to delete all unused authentication vectors for that IMSI and 
obtain new vectors from the HLR. When re-synchronisation is complete, the network shall initiate the 
authentication procedure. Upon receipt of the AUTHENTICATION REQUEST message, the MS shall stop the 
timer T3216, if running. 

NOTE: Upon receipt of two consecutive AUTHENTICATION FAILURE messages from the MS with reject 
cause "synch failure", the network may terminate the authentication procedure by sending an 
AUTHENTICATION REJECT message. 

If the network is validated successfully (a new AUTHENTICATION REQUEST is received which contains a 
valid SQN and MAC) while T3216 is running, the MS shall send the AUTHENTICATION RESPONSE 
message to the network and shall start any retransmission timers (e.g. T3210, T3220 or T3230), if they were 
running and stopped when the MS received the first failed AUTHENTICATION REQUEST message. 

If the MS receives the second AUTHENTICATION REQUEST while T3216 is running, and the MAC value 
cannot be resolved or the message contains a GSM authentication challenge, the MS shall proceed as specified in 
(c); if the SQN is invalid, the MS shall follow the procedure specified in this subclause (d), starting again fom 
the beginning. 

The MS shall deem that the network has failed the authentication check and behave as described in 
subclause 4.3.2.6. 1, if any of the following occurs: 

the timer T3216 expires; 

- the MS detects any combination of the authentication failures: "MAC failure", "invaHd SQN", and "GSM 
authentication unacceptable", during three consecutive authentication challenges. The authentication 
challenges shall be considered as consecutive only, if the authentication challenges causing the second and 
third authentication failure are received by the MS, while the timer T3214 or T3216 started after the previous 
authentication failure is running. 
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Figure 4.2a/3GPP TS 24.008: Authentication Failure Procedure (reject cause "Synchi failure") 



4.3.2.6.1 



MS behaviour towards a network that has failed the authentication procedure 



If the MS deems that the network has failed the authentication check, then it shall request RR or RRC to release the RR 
connection and the PS signalling connection, if any, and bar the active cell or cells (see 3GPP TS 25.331 [23c] and 
3GPP TS 44.018 [84]). The MS shall start any retransmission timers (e.g. T3210, T3220 or T3230), if they were 
running and stopped when the MS received the first AUTHENTICATION REQUEST message containing an invalid 
MAC or invalid SQN, or no AUTN when a UMTS authentication challenge was expected. 



4.3.2.7 



Handling of keys at intersystem change from lu mode to A/Gb mode 



At inter-system change from lu mode to A/Gb mode, ciphering may be started (see 3GPP TS 44.018 [84]) without any 
new authentication procedure. Deduction of the appropriate security key for ciphering in A/Gb mode, depends on the 
current GSM/UMTS security context stored in the MS and the network. 

The ME shall handle the GSM ciphering key and a potential GSM Kci28 according to table 4.3.2.7. 1. 

Table 4.3.2.7.1/3GPP TS 24.008: Inter-system change from lu mode to A/Gb mode 



Security context established in MS and 
network in lu mode 


At inter-system change to A/Gb mode: 


GSIVI security context 


An IVIE shall apply the stored GSIVI ciphering key that was 
received from the GSM security context residing in the SIM/USIM 
during the latest successful ciphering mode setting or security 
mode control procedure before the inter-system change. 


UIVITS security context 


If an A5 algorithm is taken into use that requires a 64-bit 
ciphering key, then an ME shall apply the stored GSM ciphering 
key that was derived by the USIM from the UMTS ciphering key 
and the UMTS integrity key and provided by the USIM during the 
latest successful ciphering mode setting or security mode control 
procedure before the inter-sytem change. 
If an A5 algorithm is taken into use that requires a 128-bit 
ciphering key, then an ME shall apply the GSM Kci28 derived by 
the ME from the UMTS ciphering key and the UMTS integrity key 
(see 3GPP TS 33.102 [5a]) provided by USIM during the lastest 
successful ciphering mode setting or security mode control 
procedure before the inter-system change (see 
subclause 4.3.2.3a). 



NOTE: A USIM with UMTS security context, passes the UMTS ciphering key, the UMTS integrity key and the 
derived GSM ciphering key to the ME independent on the current radio access being UTRAN or 
GERAN. 
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4.3.2.7a Use of established security contexts 

In A/Gb mode, in the case of an established GSM security context, the GSM ciphering key shall be loaded from the 
SIM/USIM and taken into use by the ME when any valid CIPHERING MODE COMMAND is received during an RR 
connection (the definition of a valid CIPHERING MODE COMMAND message is given in 3GPP TS 44.018 [84] 
subclause 3.4.7.2). 

In A/Gb mode, in the case of an established UMTS security context, the GSM ciphering key shall be loaded from the 
USIM and taken into use by the MS when a valid CIPHERING MODE COMMAND is received during an RR 
connection (the definition of a valid CIPHERING MODE COMMAND message is given in 3GPP TS 44.018 [84] 
subclause 3.4.7.2) which indicates an A5 ciphering algorithm that requires a 64-bit ciphering key. The network shall 
derive a GSM ciphering key from the UMTS ciphering key and the UMTS integrity key by using the conversion 
function named "c3" defined in 3GPP TS 33.102 [5a]. 

In A/Gb mode, in the case of an established UMTS security context, the UMTS ciphering key and the UMTS integrity 
key shall be loaded from the USIM in order for the ME to derive the GSM Kci28 (see 3GPP TS 33.102 [5a]) and shall 
be taken into use by the ME when a valid CIPHERING MODE COMMAND is received during an RR connection (the 
definition of a valid CIPHERING MODE COMMAND message is given in 3GPP TS 44.018 [84] subclause 3.4.7.2) 
which indicates an A5 ciphering algorithm that requires a 128-bit ciphering key. The network shall derive a GSM Kci28 
from the UMTS ciphering key and the UMTS integrity as defined in 3GPP TS 33.102 [5a]. 

In lu mode, in the case of an established GSM security context, the ME shall derive a UMTS ciphering key and a 
UMTS integrity key from the GSM ciphering key by using the conversion functions named "c4" and "c5" defined in 
3GPP TS 33.102 [5a]. The GSM ciphering key shall be loaded from the SIM/USIM and the derived UMTS ciphering 
key and UMTS integrity key shall be taken into use by the MS when a valid SECURITY MODE COMMAND 
indicating CS domain is received during an RR connection (the definition of a valid SECURITY MODE COMMAND 
message is given in 3GPP TS 25.331 [23c] and 3GPP TS 44.1 18 [111]). The network shall derive a UMTS ciphering 
key and a UMTS integrity key from the GSM ciphering key by using the conversion functions named "c4" and "c5" 
defined in 3GPP TS 33.102 [5a]. 

In lu mode, in the case of an established UMTS security context, the UMTS ciphering key and UMTS integrity key 
shall be loaded from the USIM and taken into use by the MS when a vahd SECURITY MODE COMMAND indicating 
CS domain is received during a RR connection (the definition of a valid SECURITY MODE COMMAND message is 
given in 3GPPTS 25.331 [23c] and 3GPP TS 44.118 [111]). 

In lu mode and A/Gb mode, if the MS received a valid SECURITY MODE COMMAND indicating CS domain in lu 
mode or a valid CIPHERING MODE COMMAND in A/Gb mode before the network initiates a new Authentication 
procedure and establishes a new GSM/UMTS security context, the new keys are taken into use in the MS when a new 
valid SECURITY MODE COMMAND indicating CS domain in lu mode, or a new valid CIPHERING MODE 
COMMAND in A/Gb mode, is received during the RR connection. In case of lu mode to lu mode handover, A/Gb 
mode to A/Gb mode handover, or inter-system change to A/Gb mode, the MS and the network shall continue to use the 
key from the old key set until a new valid SECURITY MODE COMMAND indicating CS domain in lu mode, or a new 
valid CIPHERING MODE COMMAND in A/Gb mode, is received during the RR connection. In case of inter-system 
change to lu mode, the MS and the network shall continue to use the keys from the old key set until the second valid 
SECURITY MODE COMMAND indicating CS domain is received during the RR connection. 

NOTE 1 : If the MS received a valid SECURITY MODE COMMAND indicating CS domain in lu mode or a valid 
CIPHERING MODE COMMAND in A/Gb mode before the inter-system change to lu mode occurs, the 
first SECURITY MODE COMMAND message after the inter-system change, which indicates CS domain 
and includes only an Integrity protection mode IE, is initiated by the UTRAN without receipt of a 
corresponding RAN AP security mode control procedure from the MSC/VLR. The only purpose of this 
SECURITY MODE COMMAND message is to activate the integrity protection, but not to load a new 
key set from the SIM/USIM (see 3GPPTS 25.331 [23c] and 3GPP TS 44.118 [111]). 

NOTE 2: If the MS did not receive any valid SECURITY MODE COMMAND indicating CS domain in lu mode 
or any valid CIPHERING MODE COMMAND in A/Gb mode before the inter-system change to lu mode 
occurs, the first SECURITY MODE COMMAND message after the inter-system change, which indicates 
CS domain, is initiated by the UTRAN on receipt of a RANAP security mode control procedure from the 
MSC/VLR. The purpose of this SECURITY MODE COMMAND message is to load a key set from the 
SIM/USIM and to activate either integrity protection or ciphering and integrity protection (see 
3GPPTS 25.331 [23c] and 3GPPTS 44.118 [111]). 
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4.3.2.8 



Handling of keys at intersystem change from A/Gb mode to lu mode 



At inter-system change from A/Gb mode to lu mode, ciphering and integrity may be started (see 

3GPP TS 25.331 [23c]) without any new authentication procedure. Deduction of the appropriate security keys for 

ciphering and integrity check in lu mode, depends on the current GSM/UMTS security context stored in the MS and the 

network. 

The ME shall handle the UMTS ciphering key and the UMTS integrity key according to table 4.3.2.8.1. 

Table 4.3.2.8.1/3GPP TS 24.008: Inter-system change from A/Gb mode to lu mode 



Security context established in MS and 
network in A/Gb mode 


At inter-system change to lu mode: 


GSIVl security context 


An IVIE shall derive the UIVITS ciphering key and the UIVITS 
integrity key from the stored GSM ciphering key that was 
provided by the SIM/USIM during the latest successful ciphering 
mode setting or security mode control procedure before the inter- 
system change. The conversion functions named "c4" and "c5" in 
3GPP TS 33.102 [5a] are used for this purpose. 


UIVITS security context 


An ME shall apply the stored UMTS ciphering key and the stored 
UMTS integrity key that were received from the UMTS security 
context residing in the USIM during the latest successful 
ciphering mode setting or security mode control procedure before 
the inter-system change. 



NOTE: A USIM with UMTS security context, passes the UMTS ciphering key, the UMTS integrity key and the 
derived GSM ciphering key to the ME independent on the current radio access being UTRAN or 
GERAN. 



4.3.2.9 



Void 



4.3.2.10 Derivation of keys at SRVCC handover from S1 mode 



4.3.2.10.1 



PDN connection with integrity protection 



At PS to CS domain change from S 1 mode due to SRVCC handover of a PDN connection for which the "null integrity 
protection algorithm" ElAO has not been used (see 3GPP TS 23.216 [126]), when the MS receives the command to 
perform handover, the MS shall derive a UMTS security context for the CS domain from the current EPS security 
context. 

The MS shall set the CKSN of the derived UMTS security context to the value of the eKSI of the EPS security context 
and derive security keys CKsrvcc and IKsrvcc as specified in 3GPP TS 33.401 [123]. The ME shall also derive the 
security key GSM ciphering key Kc from CKsrvcc and IKsrvcc using the conversion function c3 as specified in 
3GPP TS 33.102 [5a]. The MS shall apply these derived security keys, handle the STARTcs value as specified in 
3GPP TS 25.331 [23c] and replace an already established UMTS security context for the CS domain, if any, in the 
USIM, when the SRVCC handover from SI mode has been completed successfully. 

NOTE: Because of deriving a new UMTS security context for the CS domain, a new GSM ciphering key needs 
also to be derived from the new derived UMTS security keys for the CS domain (i.e. CKsrvcc and 
IKsrvcc)- Note that the new GSM ciphering key is also part of the new UMTS security context for the CS 
domain as well, as any old GSM ciphering key stored in the USIM and in the ME, belongs to an old 
UMTS security context for the CS domain and can no longer be used. 

The network shall replace an already established UMTS security context for the CS domain, if any, when the SRVCC 
handover from SI mode has been completed successfully. 



If the SRVCC handover from Slmode has not been completed successfully, the MS and the network shall delete the 
new derived GSM or UMTS security context for the CS domain. Additionally, the network shall delete the already 
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established GSM or UMTS security context for the CS domain, if the CKSN of the already established GSM or UMTS 
security context is equal to the CKSN of the new derived GSM or UMTS security context for the CS domain. 



4.3.2.10.2 



PDN connection without integrity protection 



At PS to CS domain change from S 1 mode due to SRVCC handover of a PDN connection for emergency bearer 
services for which the "null integrity protection algorithm" EIAO has been used while in S 1 mode, the MS and the 
network shall not perform key derivation. 

4.3.2.1 1 Derivation of keys at SRVCC handover from lu mode to lu mode 



4.3.2.11.1 



PDN connection with integrity protection 



At PS to CS domain change from lu mode to lu mode due to SRVCC handover of a PDN connection for which integrity 
protection has been activated, ciphering and integrity may be started (see 3GPP TS 25.331 [23c]) without any new 
authentication procedure. Deduction of the appropriate security keys for ciphering and integrity check in lu mode, 
depends on the current GSM or UMTS security context for the PS domain stored in the MS and the network. 

The ME shall handle the UMTS ciphering key and the UMTS integrity key according to table 4. 3. 2. 11.1. 
Table 4.3.2.11. 1/3GPP TS 24.008: SRVCC handover from lu mode to lu mode 



Security context for the PS domain 
established in IVIS and networl< in lu mode 


At inter-system change to lu mode: 


GSIVI security context 


An ME shall derive the GSM ciphering key (Kc') from the stored 
GPRS GSM ciphering key, which was provided by the SIM/USIM 
during the latest successful authentication, and the NONCE 
received in the command to perform handover (see 
3GPP TS 25.331 [23c]) using the key derivation function 
specified in 3GPP TS 33.102 [5a]. The ME shall use the derived 
GSM ciphering key (Kc') to derive the UMTS security keys UMTS 
ciphering key (OK') and UMTS integrity key (IK'). The conversion 
functions named "c4" and "c5" in 3GPP TS 33.102 [5a] are used 
for this purpose. The MS shall set the CKSN of the derived GSM 
security context for the OS domain to the value of the GPRS 
CKSN of the GSM security context for PS domain. Furthermore, 
the ME shall apply the new derived UMTS security keys and 
replace an already established GSM security context for the CS 
domain, if any, in the SIM/USIM, when the SRVCC handover 
from lu mode has been completed successfully. Furthermore, the 
MS shall handle the STARTcs value as specified in 
3GPP TS 25.331 [23c]). 


UIVITS security context 


An ME shall derive the UMTS security keys UMTS ciphering key 
(CK') and UMTS integrity key (IK') from the GPRS UMTS 
ciphering key and the GPRS UMTS integrity key, which were 
received from the UMTS security context for the PS domain 
residing in the USIM, and the NONCE received in the command 
to perform handover (see 3GPP TS 25.331 [23c]) as specified in 
3GPP TS 33.102 [5a]. The ME shall use the derived UMTS 
security keys to derive the GSM ciphering key (Kc') using the 
"c3" conversion function as specified in 3GPP TS 33.102 [5a]. 
The MS shall set the CKSN of the derived UMTS security context 
for the CS domain to the value of the KSI of the UMTS security 
context for PS domain. Furthermore, the ME shall apply the 
derived UMTS security keys and replace an already established 
UMTS security context for the CS domain, if any, in the USIM, 
when the SRVCC handover from lu mode has been completed 
successfully. Furthermore, the MS shall handle the STARTcs 
value as specified in 3GPP TS 25.331 [23c]). 
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NOTE 1 : For the case of an established UMTS security context for the PS domain, because of deriving a new 

UMTS security context for the CS domain, a new GSM ciphering key needs to be derived from the new 
derived UMTS security keys (i.e. CK' and IK'). Note that the new GSM ciphering key is also part of the 
new UMTS security context for the CS domain, and therefore any old GSM ciphering key stored in the 
USIM and in the ME belongs to an old UMTS security context for the CS domain and can no longer be 
taken into use. 

The network shall replace an already established GSM or UMTS security context for the CS domain, if any, when the 
SRVCC handover from lu mode to lu mode has been completed successfully. 

If the SRVCC handover from lu mode to lu mode has not been completed successfully, the MS and the network shall 
delete the new derived GSM or UMTS security context for the CS domain. Additionally, the network shall delete the 
already established GSM or UMTS security context for the CS domain, if the CKSN of the already established GSM or 
UMTS security context is equal to the CKSN of the new derived GSM or UMTS security context for the CS domain. 

4.3.2.1 1 .2 PDN connection without integrity protection 

At PS to CS domain change from lu mode to lu mode due to SRVCC handover of a PDN connection for emergency 
bearer services for which integrity protection has not been activated before the SRVCC handover, the MS and the 
network shall not perform key derivation. 

4.3.2.12 Derivation of keys at SRVCC handover from lu mode to A/Gb mode 
4.3.2.1 2.1 PDN connection with integrity protection 

At PS to CS domain change from lu mode to A/Gb mode due to SRVCC handover of a PDN connection for which 
integrity protection has been activated, ciphering may be started (see 3GPP TS 44.018 [84]) without any new 
authentication procedure. Deduction of the appropriate security key for ciphering in A/Gb mode, depends on the current 
GSM or UMTS security context for the PS domain stored in the MS and the network. 

The ME shall handle the GSM ciphering key according to table 4.3.2. 12. 1 . 
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Table 4.3.2.12.1/3GPP TS 24.008: SRVCC handover from lu mode to A/Gb mode 



Security context for the PS domain 
established in IVIS and networl< in lu mode 


At inter-system change to A/Gb mode: 


GSM security context 


An IVIE shall derive the GSM ciphering key (Kc') from the stored 
GPRS GSM ciphering key, which was provided by the SIM/USIM 
during the latest successful authentication, and the NONCE 
received in the command to perform handover (see 
3GPP TS 25.331 [23c]) using the key derivation function 
specified in 3GPP TS 33.102 [5a]. The MS shall set the CKSN of 
the derived GSM security context for the OS domain to the value 
of the GPRS CKSN of the GSM security context for PS domain. 
Furthermore, the ME shall apply the new derived GSM ciphering 
key and replace an already established GSM security context for 
the CS domain, if any, in the SIM/USIM when the SRVCC 
handover from lu mode has been completed successfully. 


UIVITS security context 


An ME shall derive the UMTS security keys UMTS ciphering key 
(CK') and UMTS integrity key (IK') from the GPRS UMTS 
ciphering key and GPRS UMTS integrity key, which were 
received from the UMTS security context for the PS domain 
residing in the USIM, and the NONCE received in the command 
to perform handover (see 3GPP TS 25.331 [23c]) as specified in 
3GPP TS 33.102 [5a]. The ME shall use the derived UMTS 
security keys to derive the GSM ciphering key (Kc') using the 
"c3" conversion function as specified in 3GPP TS 33.102 [5a]. 
Furthermore, the MS shall set the CKSN of the derived UMTS 
security context for the CS domain to the value of the KSI of the 
UMTS security context for PS domain. 
If an A5 algorithm is taken into use that requires a 64-bit long 
ciphering key, then the ME shall apply the new derived GSM 
ciphering key. 

If an A5 algorithm is taken into use that requires a 128-bit long 
ciphering key, then the ME shall use the derived UMTS security 
keys CK' and IK' to derive a GSM Kci28 (see 
3GPP TS 33.102 [5a]). After that, the ME shall apply the new 
derived GSM Kci28. 

Furthermore, the ME shall replace an already established UMTS 
security context for the CS domain, if any, in the USIM, when the 
SRVCC handover from lu mode has been completed 
successfully. 



The network shall replace an already established GSM or UMTS security context for the CS domain, if any, when the 
SRVCC handover from lu mode to A/Gb mode has been completed successfully. 

If the SRVCC handover from lu mode to A/Gb mode has not been completed successfully, the MS and the network 
shall delete the new derived GSM or UMTS security context for the CS domain. Additionally, the network shall delete 
the already established GSM or UMTS security context for the CS domain, if the CKSN of the already established 
GSM or UMTS security context is equal to the CKSN of the new derived GSM or UMTS security context for the CS 
domain. 



4.3.2.12.2 



PDN connection without integrity protection 



At PS to CS domain change from lu mode to A/Gb mode due to SRVCC handover of a PDN connection for emergency 
bearer services for which integrity protection has not been activated while in lu mode, the MS and the network shall not 
perform key derivation. 

4.3.3 Identification procedure 

The identification procedure is used by the network to request a mobile station to provide specific identification 
parameters to the network e.g. International Mobile Subscriber Identity, International Mobile Equipment Identity (see 
3GPP TS 23.003 [10]). For the presentation of the IMEI, the requirements of 3GPP TS 42.009 [5] apply. 
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4.3.3.1 Identity request by the network 

The network initiates the identification procedure by transferring an IDENTITY REQUEST message to the mobile 
station and starts the timer T3270. The IDENTITY REQUEST message specifies the requested identification 
parameters in the identity type information element. 

4.3.3.2 Identification response by the mobile station 

The mobile station shall be ready to respond to an IDENTITY REQUEST message at any time whilst a RR connection 

exists. 

Upon receipt of the IDENTITY REQUEST message the mobile station sends back an IDENTITY RESPONSE 
message. The IDENTITY RESPONSE message contains the identification parameters as requested by the network. 

Upon receipt of the IDENTITY RESPONSE the network shall stop timer T3270. 

4.3.3.3 Abnormal cases 

(a) RR connection failure: 

Upon detection of a RR connection failure before the IDENTITY RESPONSE is received, the network shall 
release all MM connections (if any) and abort any ongoing MM specific procedure. 

(b) Expiry of timer T3270: 

The identification procedure is supervised by the network by the timer T3270. At expiry of the timer T3270 the 
network may release the RR connection. In this case, the network shall abort the identification procedure and any 
ongoing MM specific procedure, release all MM connections if any, and initiate the RR connection release 
procedure as described in 3GPP TS 44.018 [84] subclause 3.5, 3GPP TS 25.331 [23c] (UTRAN lu mode only), 
or in 3GPP TS 44. 11 8 [ 111 ] (GERAN lu mode only). 

motoile station network 

ID REQ 

< Staut T3270 

ID RES 
> Stop T3270 



Figure 4.3/3GPP TS 24.008: Identification sequence 

(c) Requested identity is not available: 

If the MS cannot encode the requested identity in the IDENTITY RESPONSE message, e.g. because no valid 
SIM is available, then it shall encode the identity type as "No identity". 

4.3.4 IMSI detach procedure 
4.3.4.0 General 

The IMSI detach procedure may be invoked by a mobile station if the mobile station is deactivated or if the Subscriber 
Identity Module (see 3GPP TS 42.017 [7] and 3GPP TS 31.102 [1 12]) is detached from the mobile station or as part of 
the eCall inactivity procedure defined in subclause 4.4.7. 

In A/Gb mode and GERAN lu mode, a flag (ATT) broadcast in the L3-RR SYSTEM INFORMATION TYPE 3 
message on the BCCH is used by the network to indicate whether the detach procedure is required. The value of the 
ATT flag to be taken into account shall be the one broadcast when the mobile station was in MM idle. 

In UTRAN lu mode, a flag (ATT) in the CS domain specific system information element is used by the network to 
indicate whether the detach procedure is required. The value of the ATT flag to be taken into account shall be the one 
received when the mobile station was in MM idle. 
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If a RR connection exists and the ATT flag indicates that no detach procedure is required, the MM sublayer will release 
locally any ongoing MM connections before releasing the RR connection. If a MM specific procedure is active, the 
release of the RR connection may be delayed until the MM specific procedure is complete. 

The procedure causes the mobile station to be indicated as inactive in the network. 

The mobile station is allowed to initiate the IMSI detach procedure even if the timer T3246 is running. 

The network proceeds with the IMSI detach procedure even if NAS level mobility management congestion control is 
active. 

4.3.4.1 IMSI detach initiation by the mobile station 

The IMSI detach procedure consists only of the IMSI DETACH INDICATION message sent from the mobile station to 
the network. The mobile station then starts timer T3220 and enters the MM sublayer state IMSI DETACH INITIATED. 

If no RR connection exists, the MM sublayer within the mobile station will request the RR sublayer to establish a RR 
connection. If establishment of the RR connection is not possible because a suitable cell is not (or not yet) available 
then, the mobile station shall try for a period of at least 5 seconds and for not more than a period of 20 seconds to find a 
suitable cell. If a suitable cell is found during this time then, the mobile station shall request the RR sublayer to establish 
an RR connection, otherwise the IMSI detach is aborted. 

If a RR connection exists, the MM sublayer will release locally any ongoing MM connections before the IMSI 
DETACH INDICATION message is sent. 

The IMSI detach procedure may not be started if a MM specific procedure is active. If possible, the IMSI detach 
procedure is then delayed until the MM specific procedure is finished, else the IMSI detach is omitted. 

4.3.4.2 IMSI detach procedure in the network 

When receiving an IMSI DETACH INDICATION message, the network may set an inactive indication for the IMSI. 
No response is returned to the mobile station. After reception of the IMSI DETACH INDICATION message the 
network shall release locally any ongoing MM connections, and start the normal RR connection release procedure (see 
3GPP TS 44.018 [84] subclause 3.5 (A/Gb mode only), 3GPP TS 25.331 [23c] (UTRAN lu mode only), or in 
3GPP TS 44.118 [111] (GERAN lu mode only)). 

Only applicable for a network supporting VGCS: If an IMSI DETACH INDICATION message is received from the 
talking mobile station in a group call while the network is in service state MM CONNECTION ACTIVE (GROUP 
TRANSMIT MODE), the network shall release locally the ongoing MM connection and then go to the service state 
GROUP CALL ACTIVE. 

4.3.4.3 IMSI detach completion by the mobile station 

Timer T3220 is stopped when the RR connection is released. The mobile station should, if possible, delay the local 
release of the channel to allow a normal release from the network side until T3220 timeout. If this is not possible (e.g. 
detach at power down) the RR sublayer on the mobile station side should be aborted. 

4.3.4.4 Abnormal cases 

The following abnormal cases can be identified: 

a) Lower layer failure 

If the establishment of an RR connection is unsuccessful, or the RR connection is lost, the IMSI detach is aborted by 
the mobile station. 
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b) Access barred because of access class control 

The signalling procedure for IMSI detach shall not be started. The MS starts the signalling procedure as soon as 
possible and if still necessary, i.e. when the barred state is removed or because of a cell change, or performs a 
local detach immediately or after an implementation dependent time. 

niotoile station network 

IMS I DET IND 

> 

Figure 4.4/3GPP TS 24.008: IMSI detach sequence 

4.3.5 Abort procedure 

The abort procedure may be invoked by the network to abort any on-going MM connection establishment or already 
established MM connection. The mobile station shall treat ABORT message as compatible with current protocol state 
only if it is received when at least one MM connection exists or an MM connection is being established. 

4.3.5.1 Abort procedure initiation by the network 

The abort procedure consists only of the ABORT message sent from the network to the mobile station. Before the 
sending of the ABORT message the network shall locally release any ongoing MM connection. After the sending the 
network may start the normal RR connection release procedure. 

The Cause information element indicates the reason for the abortion. The following cause values may apply: 

# 6: Illegal ME 

#17: Network failure 

4.3.5.2 Abort procedure in the mobile station 

At the receipt of the ABORT message the mobile station shall abort any MM connection establishment or call re- 
establishment procedure and release all MM connections (if any). If cause value #6 is received the mobile station shall 
delete any TMSI, LAI and ciphering key sequence number stored in the SIM/USIM, set the update status to ROAMING 
NOT ALLOWED (and store it in the SIM/USIM according to subclause 4.1.2.2) and consider the SIM/USIM invalid 
until switch off or the SIM/USIM is removed. As a consequence the mobile station enters state MM IDLE, substate NO 
IMSI after the release of the RR connection. 

The mobile station shall then wait for the network to release the RR connection - see subclause 4.5.3.1. 

4.3.6 MM information procedure 

The MM information message support is optional in the network. 

The MM information procedure may be invoked by the network at any time during an RR connection. 

4.3.6.1 MM information procedure initiation by the network 

The MM information procedure consists only of the MM INFORMATION message sent from the network to the 
mobile station. During an RR connection, the network shall send none, one, or more MM INFORMATION messages to 
the mobile station. If more than one MM INFORMATION message is sent, the messages need not have the same 
content. 

NOTE: The network may be able to select particular instants where it can send the MM INFORMATION 

message without adding delay to, or interrupting, any CM layer transaction, e.g. immediately after the 
AUTHENTICATION REQUEST message. 
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4.3.6.2 MM information procedure in the mobile station 

When the mobile station (supporting the MM information message) receives an MM INFORMATION message, it shall 
accept the message and optionally use the contents to update appropriate information stored within the mobile station. 

If the mobile station does not support the MM information message the mobile station shall ignore the contents of the 
message and return an MM STATUS message with cause #97. 

4.4 MM specific procedures 

A MM specific procedure can only be started if no other MM specific procedure is running or no MM connection exists 
between the network and the mobile station. The end of the running MM specific procedure or the release of all MM 
connections have to be awaited before a new MM specific procedure can be started. 

During the lifetime of a MM specific procedure, if a MM connection establishment is requested by a CM entity, this 
request will either be rejected or be delayed until the running MM specific procedure is terminated (this depends on the 
implementation). 

Any MM common procedure (except IMSI detach) may be initiated during a MM specific procedure. 

Unless it has specific permission from the network (follow-on proceed) the mobile station side should await the release 
of the RR connection used for a MM specific procedure before a new MM specific procedure or MM connection 
establishment is started. 

NOTE: The network side may use the same RR connection for MM connection management. 

4.4.1 Location updating procedure 

The location updating procedure is a general procedure which is used for the following purposes: 

normal location updating (described in this subclause); 

periodic updating (see subclause 4.4.2); 

IMSI attach (see subclause 4.4.3); or 

indicating to the network that due to a manual CSG selection the MS has selected a CSG cell whose CSG 
identity and associated PLMN identity are not included in the MS's Allowed CSG list.or in the MS's Operator 
CSG Hst 

The normal location updating procedure is used to update the registration of the actual Location Area of a mobile 
station in the network. The location updating type information element in the LOCATION UPDATING REQUEST 
message shall indicate normal location updating. The conditions under which the normal location updating procedure is 
used by a mobile station in the MM IDLE state are defined for each service state in subclause 4.2.2. 

Only applicable for mobile stations supporting VGCS listening or VBS listening: A mobile station in RR group receive 
mode is in the MM IDLE state, substate RECEIVING GROUP CALL (NORMAL SERVICE) or RECEIVING GROUP 
CALL (LIMITED SERVICE). To perform a location updating, the MS in RR group receive mode shall leave the group 
receive mode, establish an independent dedicated RR connection to perform the location updating as described above 
and return to the RR group receive mode afterwards. 

The MS shall also start the normal location updating procedure: 

a) if the network indicates that the mobile station is unknown in the VLR as a response to MM connection 
establishment request; 

b) if the MS is configured to use CS fallback and SMS over SGs, or SMS over SGs only, and the TIN indicates 
"RAT-related TMSI", 

when the periodic tracking area update timer T3412 expires and the network operates in network operation 
mode II or III; or 

- when the MS enters a GERAN or UTRAN cell in network operation mode II or III and the E-UTRAN 

deactivate ISR timer T3423 is running. 
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NOTE 1: The timers T3412 and T3423 are specified in 3GPP TS 24.301 [120]. 

c) when the MS, configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a GERAN or 
UTRAN cell in network operation mode 11 or 111 and the E-UTRAN deactivate ISR timer T3423 has expired; 

d) when the MS, configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a GERAN or 
UTRAN cell after intersystem change from S 1 mode to lu or A/Gb mode, if timer T3346 is running, the TIN 
indicates "GUTl", and the location area of the current cell is the same as the stored location area. 

NOTE 2: If inter-system change is due to a mobile originating CS call, the location updating procedure can be 
performed after the RR connection is released unless the MS moves back to E-UTRAN. 

e) when the MS is both IMSl attached for GPRS and non-GPRS services and enters a new routing area where the 
network operates in network operation mode 1 and timer T3346 is running. 

f) when the network is operating in network operation mode 1, T3346 is running, T3246 is not running, and due to 
manual CSG selection the MS has selected a CSG cell whose CSG identity and associated PLMN identity are 
not included in the Allowed CSG list or in the Operator CSG list of the MS; or 

g) when the network is operating in network operation mode 1, T3346 is running, update status is not Ul 
UPDATED and the user manually selects the current PLMN. 

If the MS, configured to use CS fallback and SMS over SGs, enters a GERAN or UTRAN cell, after intersystem change 
from S 1 mode to lu or A/Gb mode due to CS fallback, and the location area of the current cell is not available, the MS 
may initiate the location updating procedure. 

To limit the number of location updating attempts made, where location updating is unsuccessful, an attempt counter is 
used. The attempt counter is reset when a mobile station is switched on or a SIM/USIM card is inserted. 

Upon successful location updating the mobile station sets the update status to UPDATED in the SlM/USlM, and stores 
the Location Area Identification received in the LOCATION UPDATING ACCEPT message in the SIM/USIM. The 
attempt counter shall be reset. 

The detailed handling of the attempt counter is described in subclauses 4.4.4.6 to 4.4.4.9. 

The Mobile Equipment shall contain a list of "forbidden location areas for roaming", as well as a list of "forbidden 
location areas for regional provision of service". These lists shall be erased when the MS is switched off or when the 
SIM/USIM is removed, and periodically (with period in the range 12 to 24 hours). When the lists are erased, the MS 
performs a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. The location area identification 
received on the BCCH that triggered the location updating request shall be added to the suitable list whenever a location 
update reject message is received with the cause "Roaming not allowed in this location area", "Location Area not 
allowed", or "No suitable cells in Location Area". The lists shall accommodate each 10 or more location area 
identifications. When the list is full and a new entry has to be inserted, the oldest entry shall be deleted. 

In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The MS 
shall construct the Location Area Identification of the cell from this chosen PLMN identity and the LAC received on the 
BCCH. If the constructed LAI is different from the stored LAI, the MS shall initiate the location updating procedure. 
The chosen PLMN identity shall be indicated to the UTRAN in the RRC INITIAL DIRECT TRANSFER message (see 
3GPP TS 25.331 [23c]). Whenever a LOCATION UPDATING REJECT message with the cause "PLMN not allowed" 
is received by the MS, the PLMN identity used to construct the LAI which triggered the location updating procedure 
shall be stored in the "forbidden PLMN list". Whenever a LOCATION UPDATING REJECT message is received by 
the MS with the cause "Roaming not allowed in this location area", "Location Area not allowed", or "No suitable cells 
in Location Area", the constructed LAI which triggered the location updating procedure shall be stored in the suitable 
list. 

The Mobile Equipment shall store a list of "equivalent PLMNs". This list is replaced or deleted at the end of each 
location update procedure, routing area update procedure and GPRS attach procedure. The stored list consists of a list of 
equivalent PLMNs as downloaded by the network plus the PLMN code of the registered PLMN that downloaded the 
list. The stored list shall not be deleted when the MS is switched off. The stored list shall be deleted if the SIM/USIM is 
removed. The maximum number of possible entries in the stored list is 16. 

The cell selection processes in the different states are described in 3GPP TS 43.022 [82] and 3GPP TS 45.008 [34]. 

The location updating procedure is always initiated by the mobile station. 
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In the case that the mobile station is initiating an emergency call but, due to cell re-selection or redirection by the 
network, it moves to a different LAI then the mobile station may delay the location updating procedure in the new LA 
until after the emergency call is completed. 

4.4.2 Periodic updating 

Periodic updating may be used to notify periodically the availability of the mobile station to the network. Periodic 
updating is performed by using the location updating procedure. The location updating type information element in the 
LOCATION UPDATING REQUEST message shall indicate periodic updating. 

The procedure is controlled by the timer T3212 in the mobile station. The MS indicates in the MS network feature 
support IE whether it supports the extended value for timer T3212. If the MS receives the Per MS T3212 IE in the 
Location Updating Accept message, the MS shall use this IE to determine the value of T3212 instead of the value of 
T3212 that is broadcast. If the MS does not receive the Per MS T3212 IE in the Location Updating Accept message, the 
MS shall use the value of T3212 that is broadcast . If the timer is not already started, the timer is started each time the 
mobile station enters the MM IDLE substate NORMAL SERVICE or ATTEMPTing TO UPDATE. When the MS 
leaves the MM Idle State the timer T3212 shall continue running until explicitly stopped. 

The timer is stopped (shall be set to its initial value for the next start) when: 

- a LOCATION UPDATING ACCEPT or LOCATION UPDATING REJECT message is received; 

- an AUTHENTICATION REJECT message is received; 

the first MM message is received, or security mode setting is completed in the case of MM connection 
establishment, except when the most recent service state is LIMITED SERVICE; 

the mobile station has responded to paging and thereafter has received the first correct layer 3 message except 
RR message; 

the mobile station is deactivated (i.e. equipment powered down or SIM/USIM removed). 

When the timer T3212 expires, the location updating procedure is started and the timer shall be set to its initial value for 
the next start. If the mobile station is in other state than MM Idle when the timer expires the location updating 
procedure is delayed until the MM Idle State is entered. 

The conditions under which the periodic location updating procedure is used by a mobile station in the MM IDLE state 
are defined for each service state in subclause 4.2.2. 

If the mobile station is in service state NO CELL AVAILABLE, LIMITED SERVICE, PLMN SEARCH or PLMN 
SEARCH-NORMAL SERVICE when the timer expires the location updating procedure is delayed until this service 
state is left. 

In A/Gb mode and GERAN lu mode, the (periodic) location updating procedure is not started if the BCCH information 
at the time the procedure is triggered indicates that periodic location shall not be used. The timeout value is broadcasted 
in the L3-RR SYSTEM INFORMATION TYPE 3 message on the BCCH, in the Control channel description IE, see 
3GPPTS 44.018 [84] subclause 10.5.2.11. 

In UTRAN lu mode, the (periodic) location updating procedure is not started if the information on BCCH or in the last 
received dedicated system information at the time the procedure is triggered indicates that periodic location shall not be 
used. The timeout value is included in the CS domain specific system information element. 

The T3212 timeout value shall not be changed in the NO CELL AVAILABLE, LIMITED SERVICE, PLMN SEARCH 
and PLMN SEARCH-NORMAL SERVICE states. 

When a change of the broadcast T3212 timeout value has to be taken into account and the timer is running (at change of 
the serving cell or, change of the broadcast value of T3212), the MS shall behave as follows: let tl be the new T3212 
timeout value and let t be the current timer value at the moment of the change to the new T3212 timeout value; then the 
timer shall be restarted with the value t modulo tl. 

When the mobile station is activated, or when a change of the broadcast T3212 timeout value has to be taken into 
account and the timer is not running, the mobile station shall behave as follows: let tl be the new T3212 timeout value, 
the new timer shall be started at a value randomly, uniformly drawn between and tl. 
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4.4.3 IMSI attach procedure 



The IMSI attach procedure is the complement of the IMSI detach procedure (see subclause 4.3.4). It is used to indicate 
the IMSI as active in the network. 

In A/Gb mode and GERAN lu mode, a flag (ATT) is broadcast in the L3-RR SYSTEM INFORMATION TYPE 3 
message. It indicates whether the attach and detach procedures are required to be used or not. 

In UTRANmode, a flag (ATT) is included in the CS domain specific system information element. It indicates whether 
the attach and detach procedures are required to be used or not. 

The IMSI attach procedure is invoked if the detach/attach procedures are required by the network and an IMSI is 
activated in a mobile station (i.e. activation of a mobile station with plug-in SIM/USIM, insertion of a card in a card- 
operated mobile station etc.) within coverage area from the network or a mobile station with an IMSI activated outside 
the coverage area enters the coverage area. The IMSI attach procedure is used only if the update status is UPDATED 
and if the stored Location Area Identification is the same as the one which is actually broadcasted on the BCCH of the 
current serving cell. In a shared network, the MS shall choose one of the PLMN identities as specified in 
3GPP TS 23.122 [14]. The MS shall use the IMSI attach procedure only if the update status is UPDATED and the 
stored Location Area Identification is equal to the combination of the chosen PLMN identity and the LAC received on 
the BCCH. Otherwise a normal location updating procedure (see subclause 4.4.1) is invoked independently of the ATT 
flag indication. 

IMSI attach is performed by using the location updating procedure. The location updating type information element in 
the LOCATION UPDATING REQUEST message shall in this case indicate IMSI attach. 

4.4.4 Generic Location Updating procedure 
4.4.4.1 Location updating initiation by the mobile station 

Any timer used for triggering the location updating procedure (e.g. T3211, T3212) is stopped if running. 

As no RR connection exists at the time when the location updating procedure has to be started, the MM sublayer within 
the mobile station will request the RR sublayer to establish a RR connection and enter state WAIT FOR RR 
CONNECTION (LOCATION UPDATE). The procedure for establishing an RR connection is described in 
3GPP TS 44.018 [84] subclause 3.3 and 3GPP TS 25.331 [23c]. 

The mobile station initiates the location updating procedure by sending a LOCATION UPDATING REQUEST 
message to the network, starts the timer T3210 and enters state LOCATION UPDATING INITIATED. The location 
updating type information element shall indicate what kind of updating is requested. 

If the MS is configured for "AttachWithlMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and the 
selected PLMN is neither the registered PLMN nor in the list of equivalent PLMNs, the MS shall include the IMSI in 
the Mobile identity IE in the LOCATION UPDATING REQUEST message. 

If the mobile station is configured to use CS fallback and SMS over SGs, or SMS over SGs only, the mobile station 
shall set the TIN to "P-TMSI" unless the mobile station had already received the EMM cause #18 during a combined 
attach procedure (see subclause 5.5. 1.3.4.3 of 3GPP TS 24.301 [120]) or a combined tracking area updating procedure 
(see subclause 5.5.3.3.4.3 of 3GPP TS 24.301 [120]) on the same PLMN, but not disabled the E-UTRAN capability. 

4.4.4.1 a Network Request for Additional mobile station Capability Information 

In A/Gb mode, the network may initiate the classmark interrogation procedure, for example, to obtain further 
information on the mobile station's encryption capabilities. 

4.4.4.2 Identification request from the network 

The network may initiate the identification procedure, e.g. if the network is unable to get the IMSI based on the TMSI 
and LAI used as identification by the mobile station (see subclause 4.3.3). 
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4.4.4.3 Authentication by the network 

The authentication procedure (see subclause 4.3.2) may be initiated by the network upon receipt of the LOCATION 
UPDATING REQUEST message from the mobile station. (See the cases defined in 3GPP TS 42.009 [5]). 

4.4.4.4 Security mode setting by the network 

In A/Gb mode, the security mode setting procedure (see 3GPP TS 44.018 [84] subclause 3.4.7) may be initiated by the 
network, e.g., if a new TMSI has to be allocated. 

In lu mode, the security mode control procedure (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) maybe 
initiated by the network, e.g., if a new TMSI has to be allocated. 

4.4.4.5 Attempt Counter 

To limit the number of location updating attempts made, where location updating is unsuccessful, an attempt counter is 
used. It counts the number of consecutive unsuccessful location update attempts. 

The attempt counter is incremented when a location update procedure fails. The specific situations are specified in 
subclause 4.4.4.9. 

The attempt counter is reset when: 

the mobile station is powered on; 
- a SIM/USIM is inserted; 

location update is successfully completed; 

location update completed with cause #1 1, #12,#13, #15 or #25 (see subclause 4.4.4.7). 
and in case of service state ATTEMPTING to UPDATE: 

a MS detects that a new location area is entered; 

expiry of timer T3212; 

location update is triggered by CM sublayer requests. 
The attempt counter is used when deciding whether to re-attempt a location update after timeout of timer T321 1 . 

4.4.4.6 Location updating accepted by the network 

If the location updating is accepted by the network a LOCATION UPDATING ACCEPT message is transferred to the 
mobile station. 

In case the identity confidentiality service is active (see subclauses 4.3.1 and 4.4.4.4), the TMSI reallocation may be 
part of the location updating procedure. The TMSI allocated is then contained in the LOCATION UPDATING 
ACCEPT message together with the location area identifier LAI. The network shall in this case start the supervision 
timer T3250 as described in subclause 4.3.1. 

In a shared network, if the MS is supporting network sharing, the network shall indicate in the LAI the PLMN identity 
of the CN operator that has accepted the location updating; if the MS is not supporting network sharing, the network 
shall indicate the PLMN identity of the common PLMN (see 3GPP TS 23.251 [109]). 

In a multi -operator core network (MOCN) with common GERAN, the network shall indicate in the LAI the common 
PLMN identity (see 3GPP TS 23.251 [109]). 

If the network wishes to prolong the RR connection to allow the mobile station to initiate MM connection establishment 
(for example if the mobile station has indicated in the LOCATION UPDATING REQUEST that it has a follow-on 
request pending) the network shall send "follow on proceed" in the LOCATION UPDATING ACCEPT and start timer 
T3255. 
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If the mobile station has indicated "CS fallback mobile terminating call" in the LOCATION UPDATING REQUEST 
message, the network shall maintain the RR connection for an implementation dependent duration to allow for mobile 
terminating call establishment. If the mobile station has also indicated in the LOCATION UPDATING REQUEST 
message that it has a follow-on request pending, it is implementation dependent whether the network proceeds with the 
mobile terminating call establishment or allows for a mobile initiated MM connection establishment. 

The mobile station receiving a LOCATION UPDATING ACCEPT message shall store the received location area 
identification LAI, stop timer T3210, reset the attempt counter and set the update status in the SIM/USIM to 
UPDATED. If the message contains an IMSI, the mobile station is not allocated any TMSI, and shall delete any TMSI 
in the SIM/USIM accordingly. If the message contains a TMSI, the mobile station is allocated this TMSI, and shall 
store this TMSI in the SIM/USIM and a TMSI REALLOCATION COMPLETE shall be returned to the network. If 
neither IMSI nor TMSI is received in the LOCATION UPDATING ACCEPT message, the old TMSI if any available 
shall be kept. 

If the MS has initiated the location updating procedure due to manual CSG selection and receives a LOCATION 
UPDATING ACCEPT message, and the MS sent the LOCATION UPDATING REQUEST message in a CSG cell, the 
MS shall check if the CSG ID and associated PLMN identity of the cell are contained in the Allowed CSG list. If not, 
the MS shall add that CSG ID and associated PLMN identity to the Allowed CSG list and the MS may add the HNB 
Name (if provided by lower layers) to the Allowed CSG list if the HNB Name is present in neither the Operator CSG 
list nor the Allowed CSG list. 

If the LAI or PLMN identity contained in the LOCATION UPDATING ACCEPT message is a member of the list of 
"forbidden location areas for regional provision of service", the list of "forbidden location areas for roaming" or the 
"forbidden PLMN list" then such entries shall be deleted. 

The network may also send a list of "equivalent PLMNs" in the LOCATION UPDATING ACCEPT message. Each 
entry of the list contains a PLMN code (MCC+MNC). The mobile station shall store the list, as provided by the 
network, except that any PLMN code that is already in the "forbidden PLMN list" shall be removed from the 
"equivalent PLMNs" list before it is stored by the mobile station. In addition the mobile station shall add to the stored 
list the PLMN code of the registered PLMN that sent the list. All PLMNs in the stored Ust shall be regarded as 
equivalent to each other for PLMN selection, cell selection/re-selection and handover. The stored list in the mobile 
station shall be replaced on each occurrence of the LOCATION UPDATING ACCEPT message. If no list is contained 
in the message, then the stored list in the mobile station shall be deleted. The list shall be stored in the mobile station 
while switched off so that it can be used for PLMN selection after switch on. 

After that, the mobile station shall act according to the presence of the "Follow-on proceed" information element in the 
LOCATION UPDATING ACCEPT; if this element is present and the mobile station has a CM application request 
pending, it shall send a CM SERVICE REQUEST to the network and proceed as in subclause 4.5.1.1. Otherwise, it 
shall start timer T3240 and enter state WAIT FOR NETWORK COMMAND. 

Furthermore, the network may grant authorisation for the mobile station to use GSM-Cordless Telephony System (CTS) 
in the Location Area and its immediate neighbourhood. The mobile should memorise this permission in non-volatile 
memory. If the "CTS permission" IE is not present in the message, the mobile is not authorised to use GSM-CTS, and 
shall accordingly delete any memorised permission. 

NOTE 1 : the interaction between CTS and GPRS procedures are not yet defined. 

The network may also send a list of local emergency numbers in the LOCATION UPDATING ACCEPT, by including 
the Emergency Number List IE. The mobile equipment shall store the list, as provided by the network, except that any 
emergency number that is already stored in the SIM/USIM shall be removed from the list before it is stored by the 
mobile equipment. If there are no emergency numbers stored on the SIM/USIM, then before storing the received list the 
mobile equipment shall remove from it any emergency number stored permanently in the ME for use in this case (see 
3GPP TS 22.101 [8]). The list stored in the mobile equipment shall be replaced on each receipt of a new Emergency 
Number List IE. 

The emergency number(s) received in the Emergency Number List IE are valid only in networks with the same MCC as 
in the cell on which this IE is received. If no list is contained in the LOCATION UPDATING ACCEPT message, then 
the stored list in the mobile equipment shall be kept, except if the mobile equipment has successfully registered to a 
PLMN with an MCC different from that of the last registered PLMN. 

The mobile equipment shall use the stored list of emergency numbers received from the network in addition to the 
emergency numbers stored on the SIM/USIM or ME to detect that the number dialled is an emergency number. 
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NOTE 2: The mobile equipment may use the emergency numbers Hst to assist the end user in determining whether 
the dialled number is intended for an emergency service or for another destination, e.g. a local directory 
service. The possible interactions with the end user are implementation specific. 

The list of emergency numbers shall be deleted at switch off and removal of the SIM/USIM. The mobile equipment 
shall be able to store up to ten local emergency numbers received from the network. 

4.4.4.7 Location updating not accepted by the network 

If the location updating cannot be accepted, the network sends a LOCATION UPDATING REJECT message to the 
mobile station. The mobile station receiving a LOCATION UPDATING REJECT message shall stop the timer T3210, 
store the reject cause, start T3240, enter state LOCATION UPDATING REJECTED await the release of the RR 
connection triggered by the network, and for all causes except #12, #15, #22 and #25 deletes the list of "equivalent 
PLMNs". If the location updating is rejected due to general NAS level mobility management congestion control, the 
network shall set the MM cause value to #22 "congestion" and assign a back-off timer T3246 (see 
3GPPTS 23.012 [140]). 

Upon the release of the RR connection, the mobile station shall take the following actions depending on the stored 
reject cause: 

# 2: (IMSI unknown in HLR); 

# 3: (Illegal MS); or 

# 6: (Illegal ME). 

The mobile station shall set the update status to ROAMING NOT ALLOWED (and store it in the SIM/USIM 
according to subclause 4.1.2.2), and delete any TMSI, stored LAI and ciphering key sequence number and shall 
consider the SIM/USIM as invalid for non-GPRS services until switch-off or the SIM/USIM is removed. 

#11: (PLMN not allowed); 

The mobile station shall delete any LAI, TMSI and ciphering key sequence number stored in the SIM/USIM, 
reset the attempt counter, and set the update status to ROAMING NOT ALLOWED (and store it in the 
SIM/USIM according to subclause 4.1.2.2). The mobile station shall store the PLMN identity in the "forbidden 
PLMN Hst". 

The MS shall perform a PLMN selection when back to the MM IDLE state according to 3GPP TS 23.122 [14]. 

An MS in GAN mode shall request a PLMN Hst in GAN (see 3GPP TS 44.318 [76b]) prior to performing a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

# 12: (Location Area not allowed); 

The mobile station shall delete any LAI, TMSI and ciphering key sequence number stored in the SIM/USIM, 
reset the attempt counter, and set the update status to ROAMING NOT ALLOWED (and store it in the 
SIM/USIM according to subclause 4.1.2.2). 

The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service". 

The MS shall perform a ceU selection when back to the MM IDLE state according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

NOTE 1 : The cell selection procedure is not applicable for an MS in GAN mode. 

# 13: (Roaming not allowed in this location area). 

The mobile station shall reset the attempt counter, and set the update status to ROAMING NOT ALLOWED 
(and store it in the SIM/USIM according to subclause 4.1.2.2). 

The mobile station shall store the LAI in the list of "forbidden location areas for roaming". 

The mobile station shall perform a PLMN selection instead of a cell selection when back to the MM IDLE state 
according to 3GPP TS 23.122 [14]. 
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An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to performing a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

# 15: (No Suitable Cells In Location Area). 

The mobile station shall reset the attempt counter, set the update status to ROAMING NOT ALLOWED (and 
store it in the SIM/USIM according to subclause 4.1.2.2). 

The mobile station shall store the LAI in the list of "forbidden location areas for roaming". 

The mobile station shall search for a suitable cell in another location area or a tracking area in the same PLMN 
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121]. 

NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode. 

# 22: (Congestion). 

If the T3246 value IE is present in the LOCATION UPDATING REJECT message and the value indicates that 
this timer is neither zero nor deactivated, the mobile station shall proceed as described below, otherwise it shall 
be considered as an abnormal case and the behaviour of the MS for this case is specified in subclause 4.4.4.9. 

The mobile station shall abort the location updating procedure, reset the attempt counter, set the MM update 
status to U2 NOT UPDATED and change to state MM IDLE sub-state ATTEMPTING TO UPDATE. 

The MS shall stop timer T3246 if it is running. 

If the LOCATION UPDATING REJECT message is integrity protected, the mobile station shall start timer 
T3246 with the value provided in the T3246 value IE. 

If the LOCATION UPDATING REJECT message is not integrity protected, the mobile station shall start timer 
T3246 with a random value from the default range specified in table 11.1. 

The mobile station stays in the current serving cell and applies the normal cell reselection process. The MM 
connection establishment is started, if still necessary, when timer T3246 expires or is stopped. 

# 25: (Not authorized for this CSG ). 

Cause #25 is only applicable in UTRAN lu mode and when received from a CSG cell. Other cases are 
considered as abnormal cases and the specification of the mobile station behaviour is given in subclause 4.4.4.9. 

If the LOCATION UPDATING REJECT message with cause #25 was received without integrity protection, 
then the MS shall discard the message. 

The MS shall reset the attempt counter, and set the update status to ROAMING NOT ALLOWED (and store it in 
the SIM/USIM according to subclause 4.1.2.2). 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the LOCATION UPDATING 
REQUEST message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry 
corresponding to this CSG ID and associated PLMN identity from the Allowed CSG list. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the LOCATION UPDATING 
REQUEST message are contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 

23.122 [14] subclause 3. lA. 

The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

Other values are considered as abnormal cases and the specification of the mobile station behaviour in those cases is 
given in subclause 4.4.4.9. 

4.4.4.8 Release of RR connection after location updating 

When the Location updating procedure is finished (see subclauses 4.4.4.6 and 4.4.4.7) the mobile station shall (except 
in the case where the mobile has a follow-on CM application request pending and has received the follow-on proceed 
indication, see subclause 4.4.4.6) set timer T3240 and enter the state WAIT FOR NETWORK COMMAND, expecting 
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the release of the RR connection. The network may decide to keep the RR connection for network initiated 
establishment of a MM connection, or to allow for mobile initiated MM connection establishment. 

Any release of the RR connection shall be initiated by the network according to subclause 3.5 in 3GPP TS 44.018 [84], 
and 3GPP TS 25.331 [23c]. If the RR connection is not released within a given time controlled by the timer T3240, the 
mobile station shall abort the RR connection. In both cases, either after a RR connection release triggered from the 
network side or after a RR connection abort requested by the MS-side, the MS shall return to state MM IDLE. 

If the MS receives the "Extended wait time" for CS domain from the lower layers when no location updating or CM 
service request procedure is ongoing, the MS shall ignore the "Extended wait time". 

At transition to state MM IDLE, substates NORMAL SERVICE or RECEIVING GROUP CALL (NORMAL 
SERVICE) or ATTEMPTING TO UPDATE either timer T3212 or timer T321 1 is started as described in 
subclause 4.4.4.9, or, timer T3246 is started as described in subclauses 4.4.4.7, 4.4.4.9 and 4.5.1.1. 

4.4.4.9 Abnormal cases on the mobile station side 

The different abnormal cases that can be identified are the following: 

a) Access barred because of access class control 

The location updating procedure is not started. The mobile station stays in the current serving cell and applies 
normal cell reselection process. The procedure is started as soon as possible and if still necessary (when the 
barred state is ended or because of a cell change). 

b) The answer to random access is an IMMEDIATE ASSIGNMENT REJECT message (A/Gb mode only) 

The location updating is not started. The mobile station stays in the chosen cell and applies normal cell selection 
process. The waiting timer T3122 is reset when a cell change occurs. The procedure is started as soon as possible 
after T3122 timeout if still necessary. 

c) Random access failure (A/Gb mode only) 

Timer T3213 is started. When it expires the procedure is attempted again if still necessary. 

NOTE 1: As specified in 3GPP TS 45.008 [34], a cell reselection then takes place, with return to the cell inhibited 
for 5 seconds if there is at least one other suitable cell. Typically the selection process will take the 
mobile station back to the cell where the random access failed after 5 seconds. 

If at the expiry of timer T3213 a new cell has not been selected due to the lack of valid information (see 
3GPP TS 45.008 [34]), the mobile station may as an option delay the repeated attempt for up to 8 seconds to 
allow cell re-selection to take place. In this case the procedure is attempted as soon as a new cell has been 
selected or the mobile station has concluded that no other cell can be selected. 

If random access failure occurs for two successive random access attempts for location updating the mobile 
station proceeds as specified below. 

d) RR connection failure 

The procedure is aborted and the mobile station proceeds as specified below. 

e) T3210 timeout 

The procedure is aborted, the RR connection is aborted and the MS proceeds as specified below. 

f) RR release without "Extended wait time" received from lower layers before the normal end of procedure. 

The procedure is aborted and the mobile station proceeds as specified below, except in the following 
implementation option case f 1 . 

f.l)RR release in lu mode (i.e. RRC connection release) with, for example, cause "Normal", "User inactivity" or 
"Directed signalling connection re-estabHshment" (see 3GPP TS 25.331 [32c] and 3GPP TS 44.118 [111]) 

The location updating procedure shall be initiated again, if the following conditions apply: 

i) The original location updating procedure was initiated over an existing RRC connection; and 
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ii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to 
the CS signalling connection (e.g. CS authentication procedures, see subclause 4.3.2), were received after the 
LOCATION UPDATING REQUEST message was transmitted. 

NOTE 2: The RRC connection release cause that triggers the re-initiation of the location updating procedure is 
implementation specific. 

g) Location updating reject, other causes than those treated in subclause 4.4.4.7, and cases of MM cause #22, if 
considered as abnormal cases according to subclause 4.4.4.7 

Upon reception of the cause codes #22, # 95, # 96, # 97, # 99 and #111 the MS should set the attempt counter to 
4. The MS waits for release of the RR connection as specified in subclause 4.4.4.8, and then proceeds as 
specified below. 

h) RR connection establishment failure without "Extended wait time" received from lower layers (lu mode only). 

The procedure is aborted and the mobile station proceeds as specified below. 

NOTE 3: Case h) covers all cases when the signalling connection cannot be established, including random access 
failure and access reject. As the RRC protocol has error specific retransmission mechanisms (see 
3GPP TS 25.331 [23c]), there is no need to distinguish between the different error cases within MM. 

i) "Extended wait time" for CS domain from the lower layers 

The MS shall abort the MM connection establishment and stop timer T3230 if still running. 

If the LOCATION UPDATING REQUEST message contained the NAS signalling low priority indication set to 
"MS is configured for NAS signalling low priority", the MS shall start timer T3246 with the "Extended wait 
time" value. 

In other cases the MS shall ignore the "Extended wait time". 

The MM connection establishment is started, if still necessary, when timer T3246 expires or is stopped. 

j) Timer T3246 is running 

The MM connection establishment shall not be initiated unless the MS is establishing an emergency call. The 
MS stays in the current serving cell and applies normal cell reselection process. The MM connection 
establishment is started, if still necessary, when timer T3246 expires or is stopped. 

In cases d) to i) (except in the case f.l) above, and, for repeated failures as defined in c) above, and for the case of cause 
code #22 received (as described in subclause 4.4.4.7 and 4.5.1.1) the mobile station proceeds as follows. Timer T3210 
is stopped if still running. The RR Connection is aborted in case of timer T3210 timeout. The attempt counter is 
incremented. The next actions depend on the Location Area Identities (stored and received from the BCCH of the 
current serving cell) and the value of the attempt counter. 

- the update status is UPDATED, and the stored LAI is equal to the one received on the BCCH from the current 
serving cell and the attempt counter is smaller than 4: 

The mobile station shall keep the update status to UPDATED, the MM IDLE sub-state after the RR connection 
release is NORMAL SERVICE. The mobile station shall memorize the location updating type used in the 
location updating procedure. It shall start timer T321 1 (or, if the conditions for cause code #22 specified in 
subclause 4.4.4.7 or subclause 4.5. 1. 1 are met, shall start timer T3246 and not start timer T321 1) when the RR 
connection is released. When timer T3211 or T3246 expires the location updating procedure is triggered again 
with the memorized location updating type; 

- either the update status is different from UPDATED, or the stored LAI is different from the one received on the 
BCCH from the current serving cell, or the attempt counter is greater or equal to 4: 

When the RR connection is released the mobile station shall delete any LAI, TMSI, ciphering key sequence 
number stored in the SIM/USIM, and list of equivalent PLMNs, set the update status to NOT UPDATED and 
enter the MM IDLE sub-state ATTEMPTING TO UPDATE (see subclause 4.2.2.2 for the subsequent actions) or 
optionally the MM IDLE sub-state PLMN SEARCH (see subclause 4.2.1.2) in order to perform a PLMN 
selection according to 3GPP TS 23.122 [14]. If the attempt counter is smaller than 4, the mobile station shall 
memorize that timer T321 1 (or, if the conditions for cause code #22 specified in subclause 4.4.4.7 or 
subclause 4.5.1.1 are met, shall start timer T3246 and not start timer T321 1) is to be started when the RR 
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connection is released, otherwise it shall memorize that timer T3212 (or, if the conditions for cause code #22 
specified in subclause 4.4.4.7 or subclause 4.5.1.1 are met, shall start timer T3246 and not start timer T3212) is 
to be started when the RR connection is released. 

4.4.4.1 Abnormal cases on the network side 

a) RR connection failure 

If a RR connection failure occurs during a common procedure integrated with the location updating procedure, the 
behaviour of the network should be according to the description of that common procedure. 

If a RR connection failure occurs when a common procedure does not exist, the location updating procedure towards 
the mobile station should be aborted. 

b) protocol error 

If the LOCATION UPDATING REQUEST message is received with a protocol error, the network should, if possible, 
return a LOCATION UPDATING REJECT message with one of the following Reject causes: 

#96: Mandatory information element error 

#99: Information element non-existent or not implemented 

#100: Conditional IE error 

#111: Protocol error, unspecified 

Having sent the response, the network should start the channel release procedure (see subclause 3.5). 

mobile station network 

LOG UPD REQ 
Start T3210 > 

LOG UPD AGC 
Stop T32 10 < 

LOG UPD REJ 

Figure 4.5/3GPP TS 24.008: Location updating sequence 

4.4.5 Void 

4.4.6 Void 



4.4.7 eCall inactivity procedure 



The eCall inactivity procedure is applicable only to an eCall only mobile station (as determined by information 
configured in USIM). The procedure shall be started when timer T3242 or timer T3243 expires or is found to have 
already expired in any MM Idle state except NO IMSI, NO CELL AVAILABLE or PLMN SEARCH. The mobile 
station shall then stop other running timers (e.g. T3211, T3212, T3213) and shall perform the IMSI detach procedure if 
required by the serving network and if the update state is Ul. The mobile station then enters MM Idle eCALL 
INACTIVE state and the mobile station shall delete any LAI, TMSI, ciphering key sequence number stored in the 
SIM/USIM and set the update state to U4 Updating Disabled. 

While in eCALL INACTIVE state, the mobile station maintains awareness of a potential serving cell in a potential 
serving network but initiates no MM signalling with the network and ignores any paging requests. 

The mobile station shall leave eCALL INACTIVE state only when one of the following events occur: 

- if the SIM or USIM is removed, the mobile station enters the NO IMSI state; 

if coverage is lost, the mobile station enters PLMN SEARCH state; 

if the mobile station is deactivated (e.g. powered off) by the user: the mobile station enters the NULL state; 
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if there is a CM request for an emergency services call: the mobile station should follow the procedure for return 
to state MM-IDLE in subclause 4.2.3 and attempt a location update. The MS then uses the MM and CM 
procedures to establish the emergency call at the earliest opportunity; or 

NOTE: If an eCall device has not successfully completed a location update procedure, PSAP callback will not be 
possible due to its calling line identity being unavailable at the PSAP. 

if there is a CM request for a call to an HPLMN designated non-emergency MSISDN for the purpose of 
accessing test and terminal reconfiguration services: the mobile station follows the procedure for return to state 
MM-IDLE in subclause 4.2.3 and attempts a normal location update. Once this is complete, further MM and CM 
procedures are used to establish the non-emergency call. 

4.5 Connection management sublayer service provision 

The concept of MM connection is introduced in this subclause. This concept is mainly a descriptive tool: The 
establishment of an MM connection by the network can be local (i.e. it is achieved by the transmission of the first CM 
layer message and without the transmission of any MM layer messages) or can be achieved by the transmission of a CM 
SERVICE PROMPT message (eg. in the case of certain ring back services). The release of an MM connection by the 
network or by the mobile station is always local, i.e. these purposes can be achieved without sending any MM messages 
over the radio interface. (On the contrary, establishment of an MM connection by the mobile station requires the 
sending of MM messages over the radio interface. An exception is VGCS, where an MM connection will be established 
as result of an uplink access procedure (see subclause 3.7.2. l.lin 3GPP TS 44.018 [84]).) 

The Mobility Management (MM) sublayer is providing connection management services to the different entities of the 
upper Connection management (CM) sublayer (see 3GPP TS 24.007 [20]). It offers to a CM entity the possibility to use 
an MM connection for the exchange of information with its peer entity. An MM connection is established and released 
on request from a CM entity. Different CM entities communicate with their peer entity using different MM connections. 
Several MM connections may be active at the same time. 

An MM connection requires an RR connection. All simultaneous MM connections for a given mobile station use the 
same RR connection. 

In the following subclauses, the procedures for establishing, re-establishing, maintaining, and releasing an MM 
connection are described, usually separately for the mobile station and the network side. 

4.5.1 IVIIVI connection establishment 

4.5.1 .1 MM connection establishment initiated by the mobile station 

Upon request of a CM entity to establish an MM connection the MM sublayer first decides whether to accept, delay, or 
reject this request: 

An MM connection establishment may only be initiated by the mobile station when the following conditions are 
fulfilled: 

- Its update status is UPDATED. 

- The MM sublayer is in one of the states MM IDLE, RR CONNECTION RELEASE NOT ALLOWED or 
MM connection active but not in MM connection active (Group call). 

An exception from this general rule exists for emergency calls (see subclause 4.5.1.5). A further exception is 
defined in the following clause. 

If an MM specific procedure is running at the time the request from the CM sublayer is received, and the 
LOCATION UPDATING REQUEST message has been sent, the request will either be rejected or delayed, 
depending on implementation, until the MM specific procedure is finished and, provided that the network has 
not sent a "follow-on proceed" indication, the RR connection is released. If the LOCATION UPDATING 
REQUEST message has not been sent, the mobile station may include a "follow-on request" indicator in the 
message. The mobile station shall then delay the request until the MM specific procedure is completed, when it 
may be given the opportunity by the network to use the RR connection: see subclause 4.4.4.6. 

In order to establish an MM connection, the mobile station proceeds as follows: 
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a) If no RR connection exists, the MM sublayer requests the RR sublayer to establish an RR connection and enters 
MM sublayer state WAIT FOR RR CONNECTION (MM CONNECTION). This request contains an 
establishment cause and a CM SERVICE REQUEST message. When the establishment of an RR connection is 
indicated by the RR sublayer, the MM sublayer of the mobile station starts timer T3230, gives an indication to 
the CM entity that requested the MM connection establishment, and enters MM sublayer state WAIT FOR 
OUTGOING MM CONNECTION. 

b) If an RR connection is available, the MM sublayer of the mobile station sends a CM SERVICE REQUEST 
message to the network, starts timer T3230, stops and resets timer T3241, gives an indication to the CM entity 
that requested the MM connection establishment, and enters: 

- MM sublayer state WAIT FOR OUTGOING MM CONNECTION, if no MM connection is active; 

- MM sublayer state WAIT FOR ADDITIONAL OUTGOING MM CONNECTION, if at least one MM 
connection is active; 

- If an RR connection exists but the mobile station is in the state WAIT FOR NETWORK COMMAND then 
any requests from the CM layer that are received will either be rejected or delayed until this state is left. 

c) Only applicable for mobile stations supporting VGCS talking: 

If a mobile station which is in the MM sublayer state MM IDLE, service state RECEIVING GROUP CALL 
(NORMAL SERVICE), receives a request from the GCC sublayer to perform an uplink access, the MM sublayer 
requests the RR sublayer to perform an uplink access procedure and enters MM sublayer state WAIT FOR RR 
CONNECTION (GROUP TRANSMIT MODE). 

When a successful uplink access is indicated by the RR sublayer, the MM sublayer of the mobile station gives an 
indication to the GCC sublayer and enters MM sublayer state MM CONNECTION ACTIVE (GROUP 
TRANSMIT MODE). 

When an uplink access reject is indicated by the RR sublayer, the MM sublayer of the mobile station gives an 
indication to the GCC sublayer and enters the MM sublayer state MM IDLE, service state RECEIVING GROUP 
CALL (NORMAL SERVICE). 

In the network, if an uplink access procedure is performed, the RR sublayer in the network provides an 
indication to the MM sublayer together with the mobile subscriber identity received in the TALKER 
INDICATION message. The network shall then enter the MM sublayer state MM CONNECTION ACTIVE 
(GROUP TRANSMIT MODE). 

d) When the MS is IMSI attached for CS services via EMM combined procedures, as described in 

3GPP TS 24.301 [120], and the MS is camping on an E-UTRAN cell, and if T3246 is not running, the MM 
sublayer requests EMM to initiate a service request procedure for CS fallback. The MM connection 
establishment is delayed until the MS changes to a GERAN or UTRAN cell. 

If the MS enters a GERAN or UTRAN cell, then the MS shall initiate the MM connection establishment and 
send a CM SERVICE REQUEST message. The MS shall include the Additional update parameters information 
element indicating "CS fallback mobile originating call". If the MS determines that it is in a different location 
area than the stored location area, the MS shall first initiate a normal location updating procedure regardless of 
Network Mode of Operation. If the location area of the current cell is not available, the MS may initiate a normal 
location updating procedure directly. The MM connection establishment is delayed until successful completion 
of the normal location updating procedure. Additionally the MS performs routing area updating as specified in 
subclause 4.7.5. If the normal location updating procedure is initiated, the MS shall indicate the "follow-on 
request pending", shall include the Additional update parameters information element indicating"CS fallback 
mobile originating call", and shall not include the MS network feature support information element in the 
LOCATION UPDATING REQUEST message. 

In case a, b and d, the CM SERVICE REQUEST message contains the: 

mobile identity according to subclause 10.5.1.4; 

mobile station classmark 2; 

ciphering key sequence number; and 
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CM service type identifying the requested type of transaction (e.g. mobile originating call establishment, 
emergency call establishment, short message service, supplementary service activation, location services). 

A MS supporting eMLPP may optionally include a priority level in the CM SERVICE REQUEST message. 

A collision may occur when a CM layer message is received by the mobile station in MM sublayer state WAIT FOR 
OUTGOING MM CONNECTION or in WAIT FOR ADDITIONAL OUTGOING MM CONNECTION. In this case 
the MM sublayer in the MS shall establish a new MM connection for the incoming CM message as specified in 

subclause 4.5.1.3. 

Upon receiving a CM SERVICE REQUEST message, the network shall analyse its content. The type of semantic 
analysis may depend on other on going MM connection(s). Depending on the type of request and the current status of 
the RR connection, the network may start any of the MM common procedures and RR procedures. 

In A/Gb mode, the network may initiate the classmark interrogation procedure, for example, to obtain further 
information on the mobile station's encryption capabilities. 

The identification procedure (see subclause 4.3.3) may be invoked for instance if a TMSI provided by the mobile 
station is not recognized. 

The network may invoke the authentication procedure (see subclause 4.3.2) depending on the CM service type. 

In A/Gb mode, the network decides also if the ciphering mode setting procedure shall be invoked (see subclause 3.4.7 
in 3GPPTS 44.018 [84]). 

In lu mode, the network decides also if the security mode control procedure shall be invoked (see 
3GPPTS 25.331 [23c] and 3GPP TS 44.118 [111]). 

NOTE 1 : If the CM_SERVICE_REQUEST message contains a priority level the network may use this to perform 
queuing and pre-emption as defined in 3GPP TS 23.067 [88]. 

In A/Gb mode, an indication from the RR sublayer that the ciphering mode setting procedure is completed, or reception 
of a CM SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile station. 

In lu mode, an indication from the RR sublayer that the security mode control procedure is completed, or reception of a 
CM SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile station. The 
procedures in subclause 4.1.1.1.1 shall always have precedence over this subclause. 

In lu mode, during a MM connection establishment for all services, except for emergency call (see subclause 4.1.1.1.1), 
the security mode control procedure with activation of integrity protection shall be invoked by the network unless 
integrity protection is already started (see subclause 4.1.1.1.1). 

The MM connection establishment is completed, timer T3230 shall be stopped, the CM entity that requested the MM 
connection shall be informed, and MM sublayer state MM CONNECTION ACTIVE is entered. The MM connection is 
considered to be active. 

If the service request cannot be accepted, the network returns a CM SERVICE REJECT message to the mobile station. 

The reject cause information element (see subclause 10.5.3.6 and annex G) indicates the reason for rejection. The 
following cause values may apply: 

#4: IMSI unknown in VLR 

#6: Illegal ME 

#17: Network failure 

#22: Congestion 

#25 Not authorized for this CSG 

#32: Service option not supported 

#33: Requested service option not subscribed 

#34: Service option temporarily out of order 
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If the service request is rejected due to general NAS level mobility management congestion control, the network shall 
set the MM cause value to #22 "congestion" and assign a back-off timer T3246 (see 3GPP TS 23.012 [140]). 

If no other MM connection is active, the network may start the RR connection release (see subclause 3.5 of 

3GPP TS 44.018 [84] (A/Gb mode only), 3GPP TS 25.331 [23c] (UTRAN lu mode only), or in 3GPP TS 44.1 18 [111] 

(GERAN lu mode only) when the CM SERVICE REJECT message is sent. 

If a CM SERVICE REJECT message is received by the mobile station, timer T3230 shall be stopped, the requesting 
CM sublayer entity informed. Then the mobile station shall proceed as follows: 

If the cause value is not #4 or #6 or #25 received from a CSG cell and the MS is in UTRAN lu mode, the MM 
sublayer returns to the previous state (the state where the request was received). Other MM connections shall not 
be affected by the CM SERVICE REJECT message. 

If cause value #4 is received, the mobile station aborts any MM connection, deletes any TMSI, LAI and 
ciphering key sequence number in the SIM/USIM, changes the update status to NOT UPDATED (and stores it in 
the SIM/USIM according to subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR NETWORK 
COMMAND. If subsequently the RR connection is released or aborted, this will force the mobile station to 
initiate a normal location updating). Whether the CM request shall be memorized during the location updating 
procedure, is a choice of implementation. 

If cause value #6 is received, the mobile station aborts any MM connection, deletes any TMSI, LAI and 
ciphering key sequence number in the SIM/USIM, changes the update status to ROAMING NOT ALLOWED 
(and stores it in the SIM/USIM according to subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR 
NETWORK COMMAND. The mobile station shall consider the SIM/USIM as invalid for non-GPRS services 
until switch-off or the SIM/USIM is removed. 

If cause value #22 is received, the T3246 value IE is present in the CM SERVICE REJECT message and the 
value indicates that this timer is neither zero nor deactivated, the MS shall check whether the CM SERVICE 
REJECT message with cause #22 is integrity protected and shall stop timer T3246 if it is running. If the message 
is integrity protected, the MS shall start timer T3246 with the value provided in the T3246 value IE. Otherwise, 
the MS shall start timer T3246 with a random value from the default range specified in table 11.1 .The MS stays 
in the current serving cell and applies normal cell reselection process. The service request procedure may be 
started by CM layer, if it is still necessary, when timer T3246 expires or is stopped. 

If cause value #22 is received, the T3246 value IE is not present in the CM SERVICE REJECT message or if the 
T3246 value IE the value indicates that this timer is zero or deactivated, the same actions as on timer expiry in 
subclause 4.5.1.2 shall be taken by the mobile station. 

If cause value #25 is received from a CSG cell and the MS is in UTRAN lu mode, the MS shall check whether 
the CM SERVICE REJECT message with cause #25 is integrity protected. If the message is not integrity 
protected, the MS shall discard the message. Otherwise, the MS shall abort any MM connection, remove the 
entry corresponding to the CSG ID and associated PLMN identity of the cell where the MS has sent the CM 
SERVICE REQUEST message from the Allowed CSG Hst if the CSG ID and associated PLMN identity are 
contained in the Allowed CSG list, and enter the MM sublayer state WAIT FOR NETWORK COMMAND. If 
the CSG ID and associated PLMN identity of the cell where the MS has sent the CM SERVICE REQUEST 
message is contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14] 
subclause 3.1 A. Subsequently, after the RR connection is released or aborted, the MS applies normal cell 
reselection process. 

If cause value #25 is received and the cell is not a CSG cell or the MS is not in UTRAN lu mode, the MS shall 
discard the CM SERVICE REJECT message. 
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4.5.1.2 Abnormal cases 

Mobile station side: 

a) RR connection failure without "Extended wait time" received from lower layers or IMSI deactivation. 

If an RR connection failure occurs, except in the following implementation option case a. 1, or the IMSI is 
deactivated during the establishment of an MM connection, the MM connection establishment is aborted, timers 
T3230 is stopped, and an indication is given to the CM entity that requested the MM connection establishment. 
This shall be treated as a rejection for establishment of the new MM connection, and the MM sublayer shall 
release all active MM connections. 

a.l) RR connection failure in lu mode (i.e. RRC connection release) with, for example, cause "Normal", "User 
inactivity" or "Directed signalling connection re-establishment" (see 3GPP TS 25.331 [23c] and 
3GPPTS 44.118 [111]) 

The MM connection establishment procedure shall be initiated again, if the following conditions apply: 

i) The original MM connection establishment was initiated over an existing RRC connection; and 

ii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to the 
CS signalling connection (e.g. CS authentication procedures, see subclause 4.3.2), were received after the 
CM SERVICE REQUEST message was transmitted. 

NOTE 1 : The RRC connection release cause that triggers the re-initiation of the MM connection establishment 
procedure is implementation specific. 

b) T3230 expiry 

If T3230 expires (i.e. no response is given but a RR connection is available) the MM connection establishment is 
aborted and the requesting CM sublayer is informed. If no other MM connection exists then the mobile station 
shall proceed as described in subclause 4.5.3.1 for release of the RR connection. Otherwise the mobile station 
shall return to the MM sublayer state where the request of an MM connection was received, i.e. to MM sublayer 
state MM connection active. Other ongoing MM connections (if any) shall not be affected. 

c) Reject cause values #95, #96, #97, #99, #100, #1 1 1 received 

The same actions as on timer expiry shall be taken by the mobile station. 

d) Random access failure or RR connection establishment failure without "Extended wait time" received from 
lower layers. 

If the mobile station detects a random access failure or RR connection establishment failure during the 
establishment of an MM connection, it aborts the MM connection establishment and gives an indication to the 
CM entity that requested the MM connection establishment. 

NOTE 2: Further actions of the mobile station depend on the RR procedures and MM specific procedures during 
which the abnormal situation has occurred and are described together with those procedures. 

e) Access barred because of access class control 

The MM connection establishment shall not be initiated. The MS stays in the current serving cell and applies 
normal cell reselection process. The MM connection establishment may be initiated by CM layer if it is still 
necessary, i.e. when access is granted or because of a cell change. 

f) Indication that a CS fallback to GERAN or UTRAN has failed 

If EMM indicates that the CS fallback to GERAN or UTRAN failed, the MM sublayer shall abort the MM 
connection establishment and inform the requesting CM sublayer. 

g) "Extended wait time" for CS domain from the lower layers 

The MS shall abort the MM connection establishment and stop timer T3230 if still running. 
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If the CM SERVICE REQUEST message contained the NAS signalling low priority indication set to "MS is 
configured for NAS signalling low priority", the MS shall start timer T3246 with the "Extended wait time" 
value. 

In other cases the MS shall ignore the "Extended wait time". 

The MM connection establishment is started, if still necessary, when timer T3246 expires or is stopped. 

h) Timer T3246 is running 

The MM connection establishment shall not be initiated unless the MS is establishing an emergency call. The 
MS stays in the current serving cell and applies normal cell reselection process. The MM connection 
establishment is started, if still necessary, when timer T3246 expires or is stopped. 

Network side: 

a) RR connection failure 

The actions to be taken upon RR connection failure within a MM common procedure are described together with 
that procedure. A RR connection failure occurring outside such MM common procedures, shall trigger the 
release of all active MM connections if any. 

b) Invalid message or message content 

Upon reception of an invalid initial message or a CM SERVICE REQUEST message with invalid content, a CM 
SERVICE REJECT message shall be returned with one of the following appropriate Reject cause indications: 

# 95: Semantically incorrect message 

# 96: Mandatory information element error 

# 97: Message type non-existent or not implemented 

# 99: Information element non-existent or not implemented 

# 100: Conditional IE error 

#111: Protocol error, unspecified 

When the CM SERVICE REJECT message has been sent, the network may start RR connection release if no 
other MM connections exist or if the abnormal condition also has influence on the other MM connections. 

4.5.1 .3 MM connection establishment initiated by the network 

4.5.1 .3.1 Mobile Terminating CM Activity 

When a CM sublayer entity in the network requests the MM sublayer to establish a MM connection, the MM sublayer 
will request the establishment of an RR connection to the RR sublayer if no RR connection to the desired mobile station 
exists. The MM sublayer is informed when the paging procedure is finished (see 3GPP TS 44.018 [84] subclause 3.3.2 
and 3GPP TS 25.331 [23c]) and the mobile station shall enter the MM state WAIT FOR NETWORK COMMAND. 

In A/Gb mode, when an RR connection is established (or if it already exists at the time the request is received), the MM 
sublayer may initiate any of the MM common procedures (except IMSI detach); it may request the RR sublayer to 
perform the RR classmark interrogation procedure, and/or the security mode setting procedure. 

In lu mode, when an RR connection is established (or if it already exists at the time the request is received), the MM 
sublayer may initiate any of the MM common procedures (except IMSI detach); it may request the RR sublayer to 
perform the security mode control procedure. 

When all MM and RR procedures are successfully completed which the network considers necessary, the MM sublayer 
will inform the requesting mobile terminating CM sublayer entity on the success of the MM connection establishment. 

If an RR connection already exists and no MM specific procedure is running, the network may also establish a new 
mobile terminating MM connection by sending a CM message with a new PD/TI combination. 
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If the MS receives the first CM message in the MM states WAIT FOR NETWORK COMMAND or RR 
CONNECTION RELEASE NOT ALLOWED, the MS shall stop and reset the timers T3240 and T3241 and shall enter 
the MM state MM CONNECTION ACTIVE. 

In A/Gb mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or 
the security mode setting fail, this is indicated to the CM layer with an appropriate error cause. 

In lu mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or the 
security mode control fail, this is indicated to the CM layer with an appropriate error cause. 

If an RR connection used for a MM specific procedure exists to the mobile station, the CM request may be rejected or 
delayed depending on implementation. When the MM specific procedure has been completed, the network may use the 
same RR connection for the delayed CM request. 

Only applicable in case of VGCS talking: 

In the MM CONNECTION ACTIVE (GROUP TRANSMIT MODE) the mobile station is in RR Group transmit mode. 
There shall be only one MM connection active. 

When in MM CONNECTION ACTIVE (GROUP TRANSMIT MODE) state, the MM sublayer in the network shall 
reject the request for the establishment of another MM connection by any CM layer. 

If the RR sublayer in the network indicates a request to perform a transfer of the mobile station from RR connected 
mode to RR Group transmit mode which will result in a transition from MM CONNECTION ACTIVE state to MM 
CONNECTION ACTIVE (GROUP TRANSMIT MODE) state in the MM sublayer, the MM sublayer shall not allow 
the transition if more than one MM connection is active with the mobile station. 

4.5.1 .3.2 Mobile Originating CM Activity $(CCBS)$ 

When a CM sublayer entity in the network requests the MM sublayer to establish a MM connection, the MM sublayer 
will request the establishment of an RR connection to the RR sublayer if no RR connection to the desired mobile station 
exists. The MM sublayer is informed when the paging procedure is finished (see 3GPP TS 44.018 [84] subclause 3.3.2 
and 3GPP TS 25.331 [23c]) and the mobile station shall enter the MM state WAIT FOR NETWORK COMMAND. 

In A/Gb mode, when an RR connection is established (or if it already exists at the time the request is received), the MM 
sublayer may initiate any of the MM common procedures (except IMSI detach), it may request the RR sublayer to 
perform the RR classmark interrogation procedure and/or the security mode setting procedure. 

In lu mode, when an RR connection is established (or if it already exists at the time the request is received), the MM 
sublayer may initiate any of the MM common procedures (except IMSI detach), it may request the RR sublayer to 
perform the security mode control procedure. 

The network should use the information contained in the Mobile Station Classmark Type 2 IE on the mobile station's 
support for "Network Initiated MO CM Connection Request" to determine whether to: 

not start this procedure (eg if an RR connection already exists), or, 

to continue this procedure, or, 

to release the newly established RR connection. 

In the case of a "Network Initiated MO CM Connection Request" the network shall use the established RR connection 
to send a CM SERVICE PROMPT message to the mobile station. 

If the mobile station supports "Network Initiated MO CM Connection Request", the MM sublayer of the MS gives an 
indication to the CM entity identified by the CM SERVICE PROMPT message and enters the MM sublayer state 
PROCESS CM SERVICE PROMPT. In the state PROCESS CM SERVICE PROMPT the MM sublayer waits for 
either the rejection or confirmation of the recall by the identified CM entity. Any other requests from the CM entities 
shall either be rejected or delayed until this state is left. 

When the identified CM entity informs the MM sublayer, that it has send the first CM message in order to start the CM 
recall procedure the MM sublayer enters the state MM CONNECTION ACTIVE. 

If the identified CM entity indicates that it will not perform the CM recall procedure and all MM connections are 
released by their CM entities the MS shall proceed according to subclause 4.5.3.1. 
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If the CM SERVICE PROMPT message is received by the MS in MM sublayer states WAIT FOR OUTGOING MM 
CONNECTION or in WAIT FOR ADDITIONAL OUTGOING MM CONNECTION then the mobile station shall send 
an MM STATUS message with cause " Message not compatible with protocol state". 

A mobile that does not support "Network Initiated MO CM Connection Request" shall return an MM STATUS message 
with cause #97 "message type non-existent or not implemented" to the network. 

If the mobile station supports "Network Initiated MO CM Connection Request" but the identified CM entity in the 
mobile station does not provide the associated support, then the mobile station shall send an MM STATUS message 
with cause "Service option not supported". In the case of a temporary CM problem (eg lack of transaction identifiers) 
then the mobile station shall send an MM STATUS message with cause "Service option temporarily out of order". 

If an RR connection already exists and no MM specific procedure is running, the network may use it to send the CM 
SERVICE PROMPT message. 

In A/Gb mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or 
the security mode setting fail, this is indicated to the CM layer in the network with an appropriate error cause. 

In lu mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or the 
security mode control fail, this is indicated to the CM layer in the network with an appropriate error cause. 

If an RR connection used for a MM specific procedure exists to the mobile station, the "Network Initiated MO CM 
Connection Request" may be rejected or delayed depending on implementation. When the MM specific procedure has 
been completed, the network may use the same RR connection for the delayed "Network Initiated MO CM Connection 
Request". 

4.5.1 .3.3 Paging response in lu mode (lu mode only) 

The network may initiate the paging procedure for CS services when the MS is IMSI attached for CS services. To 
initiate the procedure, the MM entity requests the RR sublayer to initiate paging (see 3GPP TS 25.331 [23c], 
3GPPTS 25.413 [19c] and 3GPPTS 44.118 [111]) for CS services. 

At reception of a paging message, the RR sublayer in the MS shall deliver a paging indication to the MM sublayer if the 
paging was initiated by the MM entity in the network (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) and the 
MS shall stop the timer T3246, if running. The MS shall respond with the PAGING RESPONSE message defined in 
3GPP TS 44.018 [84], subclause 9.1.25. For reasons of backward compatibility the paging response shall use the RR 
protocol discriminator. 

If the MS receives a paging request for CS services during an ongoing MM procedure, and the MS has already 
requested the establishment of a radio connection, the MS shall ignore the paging request and the MS and the network 
shall continue the MM procedure. 

4.5.1 .3.4 Paging response for CS fallback 

The network may initiate the paging procedure for CS services when the MS is IMSI attached for CS services via EMM 
combined procedures, as described in 3GPP TS 24.301 [120]. 

At reception of an indication of paging for CS services from EMM, the MS shall stop timer T3246, if it is running. The 
MM sublayer in the MS requests EMM to perform the service request procedure for CS fallback. 

After the MS changes to a GERAN or UTRAN cell, the MS shall: 

In A/Gb mode: ask for the establishment of an RR connection and proceed as if a paging has been received in the 
lower layers; 

In lu mode: ask for the establishment of an RRC connection and respond with the PAGING RESPONSE 
message defined in 3GPP TS 44.018 [84], subclause 9.1.25. For reasons of backward compatibility the paging 
response shall use the RR protocol discriminator. 

If the MS determines, before sending the response to paging, that it is in a different location area than the stored 
location area, the MS shall initiate a normal location updating procedure first, regardless of Network Mode of 
Operation. Additionally the MS performs routing area updating as specified in subclause 4.7.5. If the location area of 
the current cell is not available, the MS may initiate a normal location updating procedure directly. 
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When initiating the location updating procedure, the MS shall indicate "CS fallback mobile terminating call" in the 
Additional update parameters IE and the MS shall not include the MS network feature support IE. The MM connection 
establishment is delayed until successful completion of the normal location updating or combined routing area update 
procedure. After the completion of the normal location updating procedure, the MS shall not send the PAGING 
RESPONSE message. 

NOTE: For the race condition when the mobile station has a CM application request pending, the mobile station 
also indicates that it has a follow-on request pending. 

4.5.1 .4 Abnormal cases 

The behaviour upon abnormal events is described together with the relevant RR procedure or MM common procedure. 

In addition, the following abnormal event can be identified for CS fallback: 

a) Indication that a CS fallback to GERAN or UTRAN has failed 

If EMM indicates that the CS fallback to GERAN or UTRAN failed, the MM sublayer shall abort the paging 
response procedure. 

4.5.1 .5 MM connection establishment for emergency calls 

A MM connection for an emergency call may be established in all states of the mobility management sublayer which 
allow MM connection establishment for a normal originating call. In addition, establishment may be attempted in all 
service states where a cell is selected (see subclause 4.2.2) but not in the MM CONNECTION ACTIVE state (GROUP 
TRANSMIT MODE) state. However, as a network dependent option, a MM connection establishment for emergency 
call may be rejected in some of the states. 

When a user requests an emergency call establishment the mobile station will send a CM SERVICE REQUEST 
message to the network with a CM service type information element indicating emergency call establishment. If the 
network does not accept the emergency call request, e.g., because IMEI was used as identification and this capability is 
not supported by the network, the network will reject the request by returning a CM SERVICE REJECT message to the 
mobile station. 

The reject cause information element indicates the reason for rejection. The following cause values may apply: 

#3 "Illegal MS" 

#4 "IMSI unknown in VLR" 

#5 "IMEI not accepted" 

#6 "Illegal ME" 

#17 "Network failure" 

#22 "Congestion" 

#25 "Not authorized for this CSG" 

#32 "Service option not supported" 

#34 "Service option temporarily out of order" 

With the above defined exceptions, the procedures described for MM connection establishment in subclauses 4.5.1.1 
and 4.5.1.2 shall be followed. 

NOTE: Normally, the mobile station will be identified by an IMSI or a TMSI. However, if none of these 

identifiers is available in the mobile station, then the mobile station shall use the IMEI for identification 
purposes. The network may in that case reject the request by returning a CM SERVICE REJECT message 
with reject cause: #5 "IMEI not accepted". 
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4.5.1 .5a MM connection establishment for emergency calls for CS fallback 

When the MS is in NO CELL AVAILABLE state, camped on an E-UTRAN cell, and IMSI attached for CS services via 
EMM combined procedures, as described in 3GPP TS 24.301 [120], the MM sublayer requests EMM to initiate a 
service request procedure for mobile originating CS fallback emergency call. The MM connection establishment is 
delayed until the mobile station changes to a GERAN or UTRAN cell. After this point, the behaviour specified in 
subclause 4.5.1.5 applies. 

When the MS is not IMSI attached for CS services via EMM combined procedures, as described in 
3GPP TS 24.301 [120], and the MS is camping on an E-UTRAN cell, the MS shall perform any cell selection to 
GERAN or UTRAN (see 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]). The MM connection estabhshment is 
delayed until the MS changes to a GERAN or UTRAN cell. After this point, the behaviour specified in 
subclause 4.5.1.5 applies. 

4.5.1.6 Call re-establishment 

The re-establishment procedure allows a MS to resume a connection in progress after a radio link failure, possibly in a 
new cell and possibly in a new location area. The conditions in which to attempt call re-establishment or not depend on 
the call control state, see subclause 5.5.4 and, whether or not a cell allowing call re-establishment has been found (as 
described in 3GPP TS 45.008 [34]). MM connections are identified by their protocol discriminators and transaction 
identifiers: these shall not be changed during call re-establishment. 

The re-establishment takes place when a lower layer failure occurs and at least one MM connection is active (i.e. the 
mobile station's MM sublayer is either in state 6 "MM CONNECTION ACTIVE" or state 20 "WAIT FOR 
ADDITIONAL OUTGOING MM CONNECTION"). 

NOTE: During a re-establishment attempt the mobile station does not return to the MM IDLE state; thus no 

location updating is performed even if the mobile is not updated in the location area of the selected cell. 

No call re-establishment shall be performed for voice group and broadcast calls. 

4.5.1 .6.1 Call re-establishment, initiation by the mobile station 

NOTE: The network is unable to initiate call re-establishment. 

If at least one request to re-establish an MM connection is received from a CM entity as a response to the indication that 
the MM connection is interrupted (see subclause 4.5.2.3.) the mobile station initiates the call re-establishment 
procedure. If several CM entities request re-establishment only one re-establishment procedure is initiated. If any CM 
entity requests re-establishment, then re-establishment of all transactions belonging to all Protocol Discriminators that 
permit Call Re-establishment shall be attempted. 

Upon request of a CM entity to re-establish an MM connection the MM sublayer requests the RR sublayer to establish 
an RR connection and enters MM sublayer state WAIT FOR REESTABLISH. This request contains an establishment 
cause and a CM RE-ESTABLISHMENT REQUEST message. When the establishment of an RR connection is 
indicated by the RR sublayer, the MM sublayer of the mobile station starts timer T3230, gives an indication to all CM 
entities that are being re-established, and remains in the MM sublayer state WAIT FOR REESTABLISH. 

The CM RE-ESTABLISHMENT REQUEST message contains the 

mobile identity according to subclause 10.5.1.4; 

mobile station classmark 2; 

ciphering key sequence number. 

NOTE: Whether or not a CM entity can request re-establishment depends upon the Protocol Discriminator. The 
specifications for Short Message Service (3GPP TS 24.011 [22]), Call Independent Supplementary 
Services (3GPP TS 24.010 [21]) and Location Services (3GPP TS 44.071 [23a]) do not currently specify 
any re-establishment procedures. 

Upon receiving a CM RE-ESTABLISHMENT REQUEST message, the network shall analyse its content. Depending 
on the type of request, the network may start any of the MM common procedures and RR procedures. 
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The network may initiate the classmark interrogation procedure, for example, to obtain further information on the 
mobile station's encryption capabilities. 

The identification procedure (see subclause 4.3.3) may be invoked. 

The network may invoke the authentication procedure (see subclause 4.3.2). 

In A/Gb mode, the network decides if the security mode setting procedure shall be invoked (see 3GPP TS 44.018 [84] 
subclause 3.4.7). 

An indication from the RR sublayer that the security mode setting procedure is completed, or reception of a CM 
SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile station. 

In lu mode, the network decides if the security mode control procedure shall be invoked (see 3GPP TS 25.331 [23c] and 
3GPP TS 44.1 18 [111]). An indication from the RR sublayer that the security mode control procedure is completed, or 
reception of a CM SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile 
station. 

The MM connection re-establishment is completed, timer T3230 shall be stopped, all CM entities associated with the 
re-establishment shall be informed, and MM sublayer state MM CONNECTION ACTIVE is re-entered. All the MM 
connections are considered to be active. 

If the network cannot associate the re-establishment request with any existing call for that mobile station, a CM 
SERVICE REJECT message is returned with the reject cause: 

#38 "call cannot be identified" 

If call re-establishment cannot be performed for other reasons, a CM SERVICE REJECT is returned, the appropriate 
reject cause may be any of the following (see annex G): 

# 4 "IMSI unknown in VLR" ; 

# 6 "illegal ME"; 
#17 "network failure"; 
#22 "congestion"; 

#25 "not authorized for this CSG" ; 

#32 "service option not supported"; 

#34 "service option temporarily out of order". 

If the service request is rejected due to general NAS level mobility management congestion control, the network shall 
set the MM cause value to #22 "congestion" and assign a back-off timer T3246 (see 3GPP TS 23.012 [140]). 

Whatever the reject cause a mobile station receiving a CM SERVICE REJECT as a response to the CM RE- 
ESTABLISHMENT REQUEST shall stop T3230, release all MM connections and proceed as described in 
subclause 4.5.3.1. In addition: 

if cause value #4 is received, the mobile station deletes any TMSI, LAI and ciphering key sequence number in 
the SIM/USIM, changes the update status to NOT UPDATED (and stores it in the SIM/USIM according to 
subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR NETWORK COMMAND. If subsequently the 
RR connection is released or aborted, this will force the mobile station to initiate a normal location updating. The 
CM re-establishment request shall not be memorized during the location updating procedure. 

if cause value #6 is received, the mobile station deletes any TMSI, LAI and ciphering key sequence number in 
the SIM/USIM, changes the update status to ROAMING NOT ALLOWED (and stores it in the SIM/USIM 
according to subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR NETWORK COMMAND. The 
MS shall consider the SIM/USIM as invalid for non-GPRS services until switch-off or the SIM/USIM is 
removed. 

If cause value # 22 is received and the T3246 value IE is present and the value indicates that this timer is neither 
zero nor deactivated, the MS shall abort any MM connection, and proceed as specified in subclause 4.4.4.9. The 
MS shall stop timer T3246 if it is running. If the CM SERVICE REJECT message is integrity protected, the MS 
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shall start timer T3246 with the value provided in the T3246 value IE. If the CM SERVICE REJECT message is 
not integrity protected, the MS shall start timer T3246 with a random value from the default range specified in 
table 11.1. The MS stays in the current serving cell and applies the normal cell reselection process. The CM RE- 
ESTABLISHMENT REQUEST procedure should not be restarted when timer T3246 expires or is stopped. 

if cause value #25 is received from a CSG cell and the mobile station is in UTRAN lu mode, the MS shall check 
whether the CM SERVICE REJECT message with cause #25 is integrity protected. If the message is not 
integrity protected, the MS shall discard the message. Otherwise, the MS shall remove the entry corresponding to 
the CSG ID and associated PLMN identity of the cell where the MS has sent the CM SERVICE REQUEST 
message from the Allowed CSG list if the CSG ID and associated PLMN identity are contained in the Allowed 
CSG list, and enter the MM sublayer state WAIT FOR NETWORK COMMAND. If the CSG ID and associated 
PLMN identity of the cell where the MS has sent the CM SERVICE REQUEST message is contained in the 
Operator CSG Hst, the MS shall proceed as specified in 3GPP TS 23.122 [14] subclause 3.1 A. 

If cause value #25 is received and the cell is not a CSG cell or the MS is not in UTRAN lu mode, the MS shall 
discard the CM SERVICE REJECT message. 

4.5.1.6.2 Abnormal cases 

Mobile station side: 

a) Random access failure or RR connection establishment failure 

If the mobile station detects a random access failure or RR connection establishment failure during the re- 
establishment of an MM connection, the re-establishment is aborted and all MM connections are released. 

b) RR connection failure 

If a RR connection failure occurs, timer T3230 is stopped, the re-establishment is aborted and all active MM 
connections are released. 

c) IMSI deactivation 

If the IMSI deactivated during the re-establishment attempt then timer T3230 is stopped, the re-establishment is 
aborted and all MM connections are released. 

d) T3230 expires 

If T3230 expires (i.e. no response is given but a RR connection is available) the re-establishment is aborted, all 
active MM connections are released and the mobile station proceeds as described in subclause 4.5.3.1. 

e) Reject causes #96, #97, #99, #100, #1 1 1 received 

The mobile station shall perform the same actions as if timer T3230 had expired. 
Network side: 

a) RR connection failure 

If a RR connection failure occurs after receipt of the CM RE-ESTABLISHMENT REQUEST the network shall 
release all MM connections. 

b) Invalid message content 

Upon reception an invalid initial of message or a CM RE-ESTABLISHMENT REQUEST message with invalid 
content, a CM SERVICE REJECT message shall be returned with one of the following appropriate Reject cause 
indications: 

#96: Mandatory information element error 

#99: Information element non-existent or not implemented 

#100: Conditional IE error 

#111: Protocol error, unspecified 
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When the CM SERVICE REJECT message has been sent, the network shall release the RR connection. 

4.5.1 .7 Forced release during MO MM connection establishment 

If the mobile station's CM layer initiated the MM connection establishment but the CM layer wishes to abort the 
establishment prior to the completion of the establishment phase, the mobile station shall send a CM SERVICE 
ABORT message any time after the completion of the RR connection and not after the first CM message (e.g. SETUP) 
is sent. 

If the first CM message has already been sent, the normal release procedure defined by the appropriate CM protocol 
applies and the CM SERVICE ABORT shall not be sent. 

Sending of the CM SERVICE ABORT message is only allowed during the establishment of the first MM connection, 
where no other MM connection exists in parallel. If parallel MM connections exist already, a new connection 
establishment cannot be aborted and normal MM connection release according to subclause 4.5.3 applies after MM 
connection establishment. 

Upon transmission of the CM SERVICE ABORT message the mobile station shall set timer T3240 and enter the state 
WAIT FOR NETWORK COMMAND, expecting the release of the RR connection. 

Upon receipt of the CM SERVICE ABORT message the network shall abort ongoing processes, release the appropriate 
resources, and unless another MM connection establishment is pending, initiate a normal release of the RR connection. 

If the RR connection is not released within a given time controlled by timer T3240, the mobile station shall abort the 
RR connection. In both cases, either after a RR connection release triggered from the network side or after a RR 
connection abort requested by the mobile station side the mobile station shall return to state MM IDLE; the service state 
depending upon the current update status as specified in subclause 4.2.3. 

4.5.1 .8 MM connection establishment due to SRVCC handover 

An MM connection can be estabhshed locally in the MS due to an SRVCC handover (see 3GPP TS 23.216 [126]), i.e. 
without dedicated MM signalling. That is the case when the MS has a voice media stream carried over the PS domain 
that is handed over to the CS domain in A/Gb mode or lu mode via SRVCC. 

An MS in MM state MM IDLE shall establish the MM connection locally when it receives an indication from lower 
layers that a SRVCC handover was completed successfully. 

After completing MM connection establishment, MM layer shall indicate "MM connection establishment due to 
SRVCC handover" to upper layer and shall enter state MM CONNECTION ACTIVE. 

4.5.2 MM connection information transfer pinase 

After the MM connection has been established, it can be used by the CM sublayer entity for information transfer. 
According to the protocol architecture described in 3GPP TS 24.007 [20], each CM entity will have its own MM 
connection. These different MM connections are identified by the protocol discriminator PD and, additionally, by the 
transaction identifier TI. 

All MM common procedures may be initiated at any time while MM connections are active. Except for Short Message 
Control which uses a separate layer 2 low priority data link, no priority mechanism is defined between the CM, MM 
and RR sublayer messages. 

4.5.2.1 Sending CM messages 

A CM sublayer entity, after having been advised that a MM connection has been established, can request the transfer of 
CM messages. The CM messages passed to the MM sublayer are then sent to the other side of the interface with the PD 
and TI set according to the source entity. 

4.5.2.2 Receiving CM messages 

Upon receiving a CM message, the MM sublayer will distribute it to the relevant CM entity according to the PD value 
and TI value. However, if the received CM message is the first for the MM connection (identified by PD and TI), the 
MM sublayer will in addition indicate to the CM entity that a new MM connection has been established. 
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4.5.2.3 Abnormal cases 

RR connection failure: 

If the RR connection failure occurs during a RR or MM common procedure, the consequent actions are 
described together with that procedure. 

In other cases, the following applies: 

- Mobile station: 

The MM sublayer shall indicate to all CM entities associated with active MM connections that the MM 
connection is interrupted, the subsequent action of the MM sublayer (call re-establishment, see 4.5.1.6, or 
local release) will then depend on the decisions by the CM entities. 

Network: 

The MM sublayer shall locally release all active MM connections. As an option the network may delay the 
release of all or some of the MM connections to allow the mobile station to initiate call re-establishment. 

4.5.3 MM connection release 

An established MM connection can be released by the local CM entity. The release of the CM connection will then be 
done locally in the MM sublayer, i.e. no MM messages are sent over the radio interface for this purpose. 

4.5.3.1 Release of associated RR connection 

If all MM connections are released by their CM entities, and no RRLP procedure (see 3GPP TS 44.031 [23b]) and no 
LCS procedure over RRC (see 3GPP TS 25.331 [23c]) is ongoing, the mobile station shall set timer T3240 and enter the 
state WAIT FOR NETWORK COMMAND, expecting the release of the RR connection. 

If all MM connections are released by their CM entities and an RRLP procedure or LCS procedure over RRC is 
ongoing, the MS shall start the timer T3241 and enter the state RR CONNECTION RELEASE NOT ALLOWED. 

If the MS is expecting the release of the RR connection in MM state WAIT FOR NETWORK COMMAND and an 
RRLP procedure or LCS procedure over RRC is started, the MS shall stop the timer T3240, start the timer T3241 and 
enter the state RR CONNECTION RELEASE NOT ALLOWED. 

If the MS is in MM state RR CONNECTION RELEASE NOT ALLOWED and the ongoing RRLP procedure or LCS 
procedure over RRC is finished, the MS shall stop the timer T3241, reset and start the timer T3240 and shall enter the 
state WAIT FOR NETWORK COMMAND. 

If the MS receives the "Extended wait time" for CS domain from the lower layers when no location updating or CM 
service request procedure is ongoing, the MS shall ignore the "Extended wait time". 

In the network, if the last MM connection is released by its user, the MM sublayer may decide to release the RR 
connection. The RR connection may be maintained by the network, e.g. in order to establish another MM connection. 

If the RR connection is not released within a given time controlled by the timer T3240 or T3241, the mobile station 
shall abort the RR connection. In both cases, either after a RR connection release triggered from the network side or 
after a RR connection abort requested by the MS-side, the MS shall return to MM IDLE state; the service state 
depending upon the current update status as specified in subclause 4.2.3. 
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4.5.3.2 Uplink release in a voice group call 

(Only applicable for mobile stations supporting VGCS talking:) 

If a mobile station which is in the MM sublayer state MM CONNECTION ACTIVE (GROUP TRANSMIT MODE) 
receives a request from the GCC sublayer to perform an uplink release, the MM sublayer requests the RR sublayer to 
perform an uplink release procedure and enters the MM sublayer state RECEIVING GROUP CALL (NORMAL 
SERVICE). 

4.6 Receiving a IVIIVI STATUS message by a IVIIVI entity. 

If the MM entity of the mobile station receives a MM STATUS message no state transition and no specific action shall 
be taken as seen from the radio interface, i.e. local actions are possible. 

With the exceptions described for the responses to the CM SERVICE PROMPT message, the actions to be taken on 
receiving a MM STATUS message in the network are an implementation dependent option. 

4.7 Elementary mobility management procedures for GPRS 
services 

4.7.1 General 

This subclause describes the basic functions offered by the mobility management (GMM) sublayer at the radio interface 
(reference point Uj^/Uu). The functionality is described in terms of timers and procedures. During GMM procedures, 
procedures of CM layer services via the PS domain, e.g. SM, SMS, and SS, are suspended. 

4.7.1 .1 Lower layer failure 

The lower layers shall indicate a logical link failure or an RR sublayer failure or an RRC sublayer failure to the GMM 
sublayer. The failure indicates an error that cannot be corrected by the lower layers. 

4.7.1 .2 Ciphering of messages (A/Gb mode only) 

If ciphering is to be applied on a GMM context, all GMM messages shall be ciphered except the following messages: 

- ATTACH REQUEST; 

- ATTACH REJECT; 

- AUTHENTICATION AND CIPHERING REQUEST; 

- AUTHENTICATION AND CIPHERING RESPONSE; 

- AUTHENTICATION AND CIPHERING FAILURE; 

- AUTHENTICATION AND CIPHERING REJECT; 

- IDENTITY REQUEST; 

- IDENTITY RESPONSE; 

- ROUTING AREA UPDATE REQUEST; and 

- ROUTING AREA UPDATE REJECT. 
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4.7.1.3 P-TMSI signature 

The network may assign a P-TMSI signature to an MS in an attach, routing area update, or P-TMSI reallocation 
procedure. Only in combination with a valid P-TMSI, this P-TMSI signature is used by the MS for authentication and 
identification purposes in the subsequent attach, routing area update or detach procedure. If the MS has no valid P- 
TMSI it shall not use the P-TMSI signature in the subsequent attach, routing area update or detach procedure. Upon 
successful completion of the subsequent attach or routing area update procedure, the used P-TMSI signature shall be 
deleted. Upon completion of an MS initiated detach procedure, the used P-TMSI signature shall be deleted. Upon 
completion of a network initiated detach procedure the P-TMSI signature shall be kept, unless explicitly specified 
otherwise in subclause 4.7.4.2.2. 

4.7.1 .4 Radio resource sublayer address handling 

In A/Gb mode, while a packet TMSI (P-TMSI) is used in the GMM sublayer for identification of an MS, a temporary 
logical link identity (TLLI) is used for addressing purposes at the RR sublayer. 

In lu mode a Radio Network Temporary Identity (RNTI) identifies a user between the MS and the UTRAN or GERAN. 
The relationship between RNTI and IMSI is known only in the MS and in the UTRAN, see 3GPP TS 25.301 [128]. 

4.7.1 .4.1 Radio resource sublayer address handling (A/Gb mode only) 

This subclause describes how the RR addressing is managed by GMM. For the detailed coding of the different TLLI 
types and how a TLLI can be derived from a P-TMSI, see 3GPP TS 23.003 [10]. 

If the MS is configured for "AttachWithlMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and is 
entering a new PLMN which is neither the registered PLMN nor in the list of equivalent PLMNs, the MS should 
proceed as specified for case ii) below and use a randomly selected random TLLI for the transmission of the ATTACH 
REQUEST message. 

For all other cases, the MS shall determine the TLLI as follows: 

For an MS not supporting S 1 mode, two cases can be distinguished: 

- a vaHd P-TMSI is available in the MS; or 

- no vaHd P-TMSI is available in the MS. 

i) vaUd P-TMSI available 

If the MS has stored a valid P-TMSI, the MS shall derive a foreign TLLI from that P-TMSI and shall use it for 
transmission of the: 

ATTACH REQUEST message of any GPRS combined/non-combined attach procedure; other GMM 
messages sent during this procedure shall be transmitted using the same foreign TLLI until the ATTACH 
ACCEPT message or the ATTACH REJECT message is received; and 

- ROUTING AREA UPDATE REQUEST message of a combined/non-combined RAU procedure if the MS 
has entered a new routing area, or if the GPRS update status is not equal to GUI UPDATED. Other GMM 
messages sent during this procedure shall be transmitted using the same foreign TLLI, until the ROUTING 
AREA UPDATE ACCEPT message or the ROUTING AREA UPDATE REJECT message is received. 

After a successful GPRS attach or routing area update procedure, independent of whether a new P-TMSI is 
assigned, if the MS has stored a valid P-TMSI then the MS shall derive a local TLLI from the stored P-TMSI 
and shall use it for addressing at lower layers. 

NOTE 1 : Although the MS derives a local TLLI for addressing at lower layers, the network should not assume that 
it will receive only LLC frames using a local TLLI. Immediately after the successful GPRS attach or 
routing area update procedure, the network must be prepared to continue accepting LLC frames from the 
MS still using the foreign TLLI. 

ii) no valid P-TMSI available 

When the MS has not stored a valid P-TMSI, i.e. the MS is not attached to GPRS, the MS shall use a randomly 
selected random TLLI for transmission of the: 
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ATTACH REQUEST message of any combined/non-combined GPRS attach procedure. 

The same randomly selected random TLLI value shall be used for all message retransmission attempts and for 
the cell updates within one attach attempt. 

Upon receipt of an ATTACH REQUEST message, the network shall assign a P-TMSI to the MS. The network 
derives a local TLLI from the assigned P-TMSI, and transmits the assigned P-TMSI to the MS. 

Upon receipt of the assigned P-TMSI, the MS shall derive the local TLLI from this P-TMSI and shall use it for 
addressing at lower layers. 

NOTE 2: Although the MS derives a local TLLI for addressing at lower layers, the network should not assume that 
it will receive only LLC frames using a local TLLI. Immediately after the successful GPRS attach, the 
network must be prepared to continue accepting LLC frames from the MS still using the random TLLI. 

In both cases the MS shall acknowledge the reception of the assigned P-TMSI to the network. After receipt of the 
acknowledgement, the network shall use the local TLLI for addressing at lower layers. 

For an MS supporting S 1 mode, the following five cases can be distinguished: 

a) the TIN indicates "P-TMSI" or "RAT-related TMSI" and the MS holds a valid P-TMSI and a RAI; 

b) the TIN indicates "GUTI" and the MS holds a valid GUTI; 

c) the TIN is deleted and the MS holds a valid P-TMSI and RAI; 

d) the TIN is deleted and the MS holds a valid GUTI, but no valid P-TMSI and RAI; or 

e) none of the previous cases is fulfilled. 

In case a) the MS shall derive a foreign TLLI from the P-TMSI and proceed as specified for case i) above. 

In case b), the MS shall derive a P-TMSI from the GUTI and then a foreign TLLI from this P-TMSI and proceed as 
specified for case i) above. 

NOTE 3: The mapping of the GUTI to the P-TMSI is specified in 3GPP TS 23.003 [4]. 

In case c) the MS shall derive a foreign TLLI from the P-TMSI and proceed as specified for case i) above. 

In case d) the MS shall derive a P-TMSI from the GUTI and then a foreign TLLI from this P-TMSI and proceed as 
specified for case i) above. 

In case e) the MS shall proceed as as specified for case ii) above. 

4.7.1.5 P-TMSI handling 

4.7.1 .5.1 P-TMSI handling in A/Gb mode 

If a new P-TMSI is assigned by the network the MS and the network shall handle the old and the new P-TMSI as 
follows: 

Upon receipt of a GMM message containing a new P-TMSI the MS shall consider the new P-TMSI and new RAI and 
also the old P-TMSI and old RAI as valid in order to react to paging requests and downlink transmission of LLC 
frames. For uplink transmission of LLC frames the new P-TMSI shall be used. 

The MS shall consider the old P-TMSI and old RAI as invalid as soon as an LLC frame is received with the local TLLI 
derived from the new P-TMSI. 

Upon the transmission of a GMM message containing a new P-TMSI the network shall consider the new P-TMSI and 
new RAI and also the old P-TMSI and old RAI as valid in order to be able to receive LLC frames from the MS. 

The network shall consider the old P-TMSI and old RAJ as invalid as soon as an LLC frame is received with the local 
TLLI derived from the new P-TMSI. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



119 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



4.7.1.5.2 



P-TMSI handling in lu mode 



If a new P-TMSI is assigned by the network the MS and the network shall handle the old and the new P-TMSI as 
follows: 

Upon receipt of a GMM message containing a new P-TMSI the MS shall consider the new P-TMSI and new RAI as 
valid. Old P-TMSI and old RAI are regarded as invalid. 

The network shall consider the old P-TMSI and old RAI as invalid as soon as an acknowledge message (e.g. ATTACH 
COMPLETE, ROUTING AREA UPDATE COMPLETE and P-TMSI REALLOCATION COMPLETE) is received. 



4.7.1.5.3 



Void 



4.7.1.5.4 



Void 



4.7.1.6 



Change of network mode of operation 



In the following tables below the abbreviations 'A/Gb mode I', 'A/Gb mode 11' and 'A/Gb mode III' are used for network 
operation mode I, II and III in A/Gb mode. 

In the following tables below the abbreviations 'lu mode I' and 'lu mode 11' are used for network operation modes I and 
II in lu mode. 



4.7.1.6.1 



Change of network mode of operation in A/Gb mode (A/Gb mode only) 



Whenever an MS moves to a new RA, the procedures executed by the MS depend on the network mode of operation in 
the old and new routing area. 

a) In case the MS is in state GMM-REGISTERED or GMM-ROUTING-AREA-UPDATING-INITIATED and is in 
operation mode A or B (with the exceptions in b, c and d below), the MS shall execute according to 
table 4.7.1.6.1-1: 

Table 4.7.1 .6.1-1/3GPP TS 24.008: Mode A or B 



Network operation 
mode change 


Procedure to execute 


1^ II origin 


Normal Location Update(*), 

followed by a Normal Routing Area Update 


II ^111 or III ^11 


Normal Location Update (see subclause 4.2.2) if a new LA is entered, 
followed by a Normal Routing Area Update 


II ^ lor III ^1 


Combined Routing Area Update with IMSI attach(**) 



b) In case the MS is in state GMM-REGISTERED or GMM-ROUTING-AREA-UPDATING-INITIATED, and 
reverts to operation mode C in network operation mode III, the MS shall execute according to table 4.7.1.6.1-2: 

Table 4.7.1.6.1-2/3GPP TS 24.008: Mode B which reverts into mode C in network operation mode III 



Networl< operation 
mode change 


Procedure to execute 


l^ll 


Normal Location Update(*), 

followed by a Normal Routing Area Update 


1^ III or II ^111 


IIVISI Detach (see subclause 4.3.4), 
followed by a Normal Routing Area Update 


II ^ lor III ^1 


Combined Routing Area Update with IMSI attach(**) 


III ^11 


IIVISI attach (see subclause 4.4.3), 
followed by a Normal Routing Area Update 



c) In case the MS is in state GMM-REGISTERED or GMM-ROUTING-AREA-UPDATING-INITIATED, and 
reverts to IMSI attached for CS services only in network operation mode III, the MS shall execute according to 
table 4.7.1.6.1-3: 
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Table 4.7.1 .6.1 -3/3GPP TS 24.008: Mode B which reverts into IIUIS! attached for CS services only in 

network operation mode III 



Network operation 
mode change 


Procedure to execute 


l^ll 


Normal Location Update(*), 

followed by a Normal Routing Area Update 


l^lll 


Normal Location Update(*), 

followed by a GPRS Detach with type indicating "GPRS Detach" 


II ^111 


Normal Location Update (see subclause 4.2.2) if a new LA is entered, 
followed by a GPRS Detach with detach type indicating "GPRS Detach" 


11-^1 


Combined Routing Area Update with IMS! attach(**) 



d) In case the MS is capable of operation mode B, but reverts to IMSI attached for CS services only in network 
operation mode III, and the MS is currently IMSI attached, the MS shall execute according to table 4.7.1.6.1-4: 

Table 4.7.1 .6.1 -4/3GPP TS 24.008: IVIode B which reverts into IMSI attached for CS services only in 
network operation mode III while in network mode III 



Network operation 
mode change 


Procedure to execute 


lll^l 


Combined GPRS Attach(**) 


lll^ll 


Normal Location Update (see subclause 4.2.2) if a new LA is entered, 
followed by a Normal GPRS Attach 



(*) Intended to remove the Gs association in the MSC/VLR. 

(**) Intended to establish the Gs association in the MSC/VLR. 

Further details are implementation issues. 



4.7.1.6.2 



Change of network mode of operation in lu mode (lu mode only) 



Whenever an MS moves to a new RA, the procedures executed by the MS depend on the network mode of operation in 
the old and new routing area. 

In case the MS is in state GMM-REGISTERED or GMM-ROUTING-AREA-UPDATING-INITIATED and is in 
operation mode A, the MS shall execute: 

Table 4.7.1 .6.4/3GPP TS 24.008: Mode A 



Network operation 
mode change 


Procedure to execute 


l^ll 


Normal Location Update(*), 

followed by a Normal Routing Area Update 


ll^l 


Combined Routing Area Update with IMSI attach(**) 



(*) Intended to remove the Gs association in the MSC/VLR. 

(**) Intended to establish the Gs association in the MSC/VLR. 

Further details are implementation issues. 

4.7.1 .6.3 Change of network mode of operation at lu mode to A/Gb mode inter-system 

change 

Whenever an MS moves to a new RA supporting the A/Gb mode radio interface, the procedures executed by the MS 
depend on the network mode of operation in the old and new routing area. 

In case the MS is in state GMM-REGISTERED or GMM-ROUTING-AREA-UPDATING-INITIATED and is in 
operation mode: 
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a) A in lu mode, an MS that changes to GPRS operation mode A or B in A/Gb mode shall execute: 
Table 4.7.1. 6.5/3GPP TS 24.008: Mode A in lu mode changing to GPRS mode A or B in A/Gb mode 



Network operation 
mode change 


Procedure to execute 


lu mode 1 -> A/Gb mode 1 


Combined Routing Area Update 


lu mode II -> /VGb mode 1 


Combined Routing Area Update witli IMSI attach(**) 


lu mode 1 -> A/Gb mode II 

or 

lu mode 1 -> A/Gb mode 

III 


Normal Location Update(*), 

followed by a Normal Routing Area Update 



b) A in lu mode, an MS that changes due to MS specific characteristics to GPRS operation mode C in network 
operation mode III in A/Gb mode shall execute: 

Table 4.7.1 .6.6/3GPP TS 24.008: Mode A in lu mode changing to GPRS mode C in A/Gb mode 



Network operation 
mode change 



Procedure to execute 



lu mode I - 

III or 

lu mode II 



■ A/Gb mode 



■ A/Gb mode 



IIVISI detach (see subclause 4.3.4), 
followed by a Normal Routing Area Update 



c) A in lu mode, an MS that changes due to MS specific characteristics to IMSI attached for CS services only in 
network operation mode III in A/Gb mode shall execute: 

Table 4.7.1. 6.7/3GPP TS 24.008: Mode A in lu mode changing to IMSI attached for CS services only in 

A/Gb mode 



Network operation 
mode change 


Procedure to execute 


lu mode 1 -^ A/Gb mode 
III 


Normal Location Update (see subclause 4.4.1 )(*), 

followed by a GPRS Detach with detach type indicating "GPRS Detach" 


lu mode II — > /VGb mode 
III 


Normal Location Update (see subclause 4.4.1) if a new LA is entered, 
followed by a GPRS Detach with detach type indicating "GPRS Detach" 



d) C in lu mode, the MS shall change to GPRS operation mode C in A/Gb mode and shall execute the normal 
Routing Area Update procedure. 

e) CS in lu mode, the MS shall execute the normal Location Update procedure. 
(*) Intended to remove the Gs association in the MSC/VLR. 

(**) Intended to establish the Gs association in the MSC/VLR. 

Further details are implementation issues. 

4.7.1 .6.4 Change of network mode of operation at A/Gb mode to lu mode inter-system 

change 

Whenever an MS moves to a new RA supporting the lu mode radio interface, the procedures executed by the MS 
depend on the network mode of operation in the old and new routing area. 

In case the MS is in state GMM-REGISTERED or GMM-ROUTING-AREA-UPDATING-INITIATED and is in 
operation mode: 
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a) A or B in A/Gb mode, the MS shall change to operation mode A in lu mode and shall execute: 
Table 4.7.1 .6.8/3GPP TS 24.008: Mode A or B in A/Gb mode changing to mode A in lu mode 



Network operation mode 
change 



Procedure to execute 



A/Gb mode I -> lu mode I 



Combined Routing Area Update 



/VGb mode II -^ lu mode I 



Combined Routing Area Update with IMSI attach(**) 



/VGb mode I -> lu mode II 



Normal Location Update(*), 

followed by a Normal Routing Area Update 



/VGb mode II -^ lu mode II 

or 

/VGb mode III -^ lu mode II 



Normal Location Update if a new LA is entered, 
followed by a Normal Routing Area Update 



b) C in A/Gb mode, an MS that changes to operation mode C in lu mode shall execute a Normal Routing Area 
Update. 

c) C in A/Gb mode, an MS that, due to MS specific characteristics operated in GPRS operation mode C in 
network operation mode III in A/Gb mode changes to operation mode A in lu mode shall execute: 

Table 4.7.1. 6.9/3GPP TS 24.008: Mode C changing to mode A in lu mode 



Networl< operation 
mode change 


Procedure to execute 


/VGb mode III -^ lu mode 

1 


Combined Routing Area Update with IMSI attachf*) 


/VGb mode III -^ lu mode 
II 


IMSI attach (see subclause 4.4.3), 
followed by a Normal Routing Area Update 



d) IMSI attached for non-GPRS services only, an MS that, due to MS specific characteristics, operated in 
network operation mode III in A/Gb mode and changes to operation mode A in lu mode shall execute: 

Table 4.7.1. 6.1 0/3GPP TS 24.008: IMSI attached for non-GPRS services only changing to mode A in lu 

mode 



Networl< operation 
mode change 


Procedure to execute 


/VGb mode III -> lu mode 

1 


Combined GPRS Attach for GPRS and non-GPRS services(**) 


/VGb mode III -^ lu mode 
II 


GPRS Attach 



(*) Intended to remove the Gs association in the MSC/VLR. 

(**) Intended to establish the Gs association in the MSC/VLR. 

Further details are implementation issues. 



4.7.1.7 



Intersystem change between A/Gb mode and lu mode 



For the lu mode to A/Gb mode and A/Gb mode to lu mode intersystem change the following cases can be 
distinguished: 

a) Intersystem change between cells belonging to different RA's: 

The procedures executed by the MS depends on the network mode of operation in the old and new RA. If a 
change of the network operation mode has occurred in the new RA, then the MS shall behave as specified in 
subclause 4.7.1.6. If no change of the network operation mode has occurred in the new RA, then the MS shall 
initiate the normal or combined RA update procedure depending on the network operation mode in the current 
RA. 

b) Intersystem change between cells belonging to the same RA: 
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1) If the READY timer is ranning in the MS in A/Gb mode or the MS is in PMM-CONNECTED mode in lu 
mode, then the MS shall perform a normal or combined RA update procedure depending on the network 
mode of operation in the current RA. 

2) If the READY timer is not running in the MS in A/Gb mode or the MS is in PMM-IDLE mode in lu mode, 
then the MS shall not perform a RA update procedure (as long as the MS stays within the same RA) until up- 
link user data or signalling information needs to be sent from the MS to the network, except case c) or case 
b) 3) below is applicable. 

If the MS is in the same access network, A/Gb mode or lu mode, as when it last sent user data or 
signalling messages, the procedures defined for that access system shall be followed. This shall be 
sending of an LLC PDU in a A/Gb mode cell or initiating the SERVICE REQUEST procedure in an lu 
mode cell. 

If the MS is in a different access network, A/Gb mode or lu mode, as when it last sent user data or 
signalling messages, the normal or combined RA update procedure shall be performed depending on the 
network operation mode in the current RA, before the sending of user data or signalling messages. If the 
signalling message is a DETACH REQUEST containing cause "power off", the RA update procedure 
need not to be performed. 

If the periodic routing area update timer expires the MS shall initiate the periodic RA update procedure. 

3) If the READY timer is not running in the MS in A/Gb mode or the MS is in PMM-IDLE mode in lu mode, 
then the MS shall perform a normal or combined RA update procedure depending on the network mode of 
operation in the current RA if the MS is required to perform routing area updating for IMS voice termination 
as specified in annex P. 3. 

4) If the READY timer is not running in the network in A/Gb mode or the network is in PMM-IDLE mode in lu 
mode, then the network shall page the MS if down-link user data or signalling information needs to be sent 
from the network to the MS. This shall include both A/Gb mode and lu mode cells. 

If the MS receives the paging indication in the same access network, A/Gb mode or lu mode, as when it 
last sent user data or signalling information, the MS shall send any LLC PDU in a A/Gb mode cell or 
shall initiate the SERVICE REQUEST procedure indicating service type "paging response" in an lu mode 
cell. 

If the MS receives the paging indication in a different access network, A/Gb mode or lu mode, as when it 
last sent user data or signalling information, the normal or combined RA update procedure shall be 
performed depending on the network operation mode in the current RA. 

c) Intersystem handover from A/Gb mode to lu mode during a CS connection: 

After the successful completion of the handover from an A/Gb mode cell to an lu mode cell, an MS which has 
performed the GPRS suspension procedure in Gb mode (see 3GPP TS 44.018 [84]) (i.e. an MS in MS operation 
mode B or an DTM MS in a A/Gb mode cell that does not support DTM) shall perform a normal RA update 
procedure in the lu mode cell in order to resume the GPRS services in the network, before sending any other 
signalling messages or user data. 

4.7.1 .8 List of forbidden PLMNs for GPRS service 

The Mobile Equipment shall contain a list of "forbidden PLMNs for GPRS service". This lists shall be erased when the 
MS is switched off or when the SIM/USIM is removed. The PLMN identification received on the BCCH shall be added 
to the list whenever a GPRS attach or routing area update is rejected by the network with the cause "GPRS services not 
allowed in this PLMN" or whenever a GPRS detach is initiated by the network with the cause "GPRS services not 
allowed in this PLMN". 

In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The PLMN 
identity chosen for a GPRS attach procedure, or the PLMN identity used to construct the RAI that triggered the routing 
area updating procedure shall be added to the list of "forbidden PLMNs for GPRS service" whenever such a procedure 
is rejected by the network with the cause "GPRS services not allowed in this PLMN". Whenever a GPRS detach is 
initiated by the network with the cause "GPRS services not allowed in this PLMN", the chosen PLMN identity shall be 
added to the list of "forbidden PLMNs for GPRS service". 
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The maximum number of possible entries in this list is implementation dependent, but must be at least one entry. When 
the list is full and a new entry has to be inserted, the oldest entry shall be deleted. 

4.7.1 .8a Establishment of the PS signalling connection (lu mode only) 

In order to route the NAS message to an appropriate SGSN, the MS NAS provides the lower layers with the routing 
parameter according to the following rules: 

a) if the TIN indicates "P-TMSI" or "RAT-related TMSI", and the MS holds a valid P-TMSI, the MS NAS shall 
provide the lower layers with the P-TMSI; 

b) if the TIN indicates "GUTI" and the MS holds a valid GUTI, the MS NAS shall provide the lower layers with 
the P-TMSI mapped from the GUTI (see 3GPP TS 23.003 [10]); 

c) if the TIN is not available and the MS holds a valid P-TMSI, the MS NAS shall provide the lower layers with the 
P-TMSI; or 

d) if the TIN is not available and the MS holds a valid GUTI, but no valid P-TMSI, the MS NAS shall provide the 
lower layers with the P-TMSI mapped from the GUTI (see 3GPP TS 23.003 [10]). 

4.7.1 .9 Release of the PS signalling connection (lu mode only) 

In lu mode, to allow the network to release the PS signalling connection (see 3GPP TS 25.331 [23c] and 
3GPP TS 44.118 [111]) the MS shall start the timer T3340 in the following cases: 

a) the MS receives any of the reject cause values #11, #12, #13, #15 or #25; 

b) the network indicates "no follow-on proceed" in the ROUTING AREA UPDATE ACCEPT or ATTACH 
ACCEPT message; or 

c) the MS receives a DETACH ACCEPT message while the T3346 timer is running and the MS has set the detach 
type to "IMSI detach" in the DETACH REQUEST message and user plane radio access bearers have not been 
set up. 

Upon expiry of T3340, the MS shall release the established PS signalling connection (see 3GPP TS 25.331 [23c] and 
3GPPTS 44.118 [111]). 

In case b, if the MS has signalling pending, then it shall request a new PS signalling connection for further signalling. 

In case c, 

upon an indication from the lower layers that radio access bearer(s) is set up, the MS shall stop timer T3340 and 
may send uplink signalling via the existing PS signalling connection or user data via radio access bearer(s); or 

upon receipt of a DETACH REQUEST message, the MS shall stop timer T3340 and respond to the network 
initiated GPRS detach as specified in subclause 4.7.4.2. 

If the MS receives the "Extended wait time" for PS domain from the lower layers when no attach, routing area updating 
or service request procedure is ongoing, the MS shall ignore the "Extended wait time". 

4.7.2 GPRS Mobility management timers and UMTS PS signalling 
connection control 

4.7.2.1 READY timer behaviour 

4.7.2.1 .1 READY timer behaviour (A/Gb mode only) 

The READY timer, T3314 is used in the MS and in the network per each assigned P-TMSI to control the cell updating 
procedure. 
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When the READY timer is running or has been deactivated the MS shall perform cell update each time a new cell is 
selected (see 3GPP TS 43.022 [82]). If a routing area border is crossed, a routing area updating procedure shall be 
performed instead of a cell update. 

When the READY timer has expired: 

the MS shall perform the routing area updating procedure when a routing area border is crossed; 

the MS shall not perform a cell update when a new cell is selected. 

the network shall page the MS if down-link user data or signalling information needs to be sent to the MS. 

All other GMM procedures are not affected by the READY timer. 

The READY timer is started: 

in the MS when the GMM entity receives an indication from lower layers that an LLC frame other than LLC 
NULL frame has been transmitted on the radio interface; and 

in the network when the GMM entity receives an indication from lower layers that an LLC frame other than LLC 
NULL frame has been successfully received by the network. 

Within GMM signalling procedures the network includes a "force to standby" information element, in order to indicate 
whether or not the READY timer shall be stopped when returning to the GMM -REGISTERED state. If the "force to 
standby" information element is received within more than one message during a ongoing GMM specific procedure, the 
last one received shall apply. If the READY timer is deactivated and the network indicates "force to standby" with the 
"force to standby" information element, this shall not cause a modification of the READY timer. 

The READY timer is not affected by state transitions to and from the GMM-REGISTERED.SUSPENDED sub-state. 

The value of the READY timer may be negotiated between the MS and the network using the GPRS attach or GPRS 
routing area updating procedure. 

If the MS wishes to indicate its preference for a READY timer value it shall include the preferred values into the 
ATTACH REQUEST and/or ROUTING AREA UPDATE REQUEST messages. The preferred values may be 
smaller, equal to or greater than the default values or may be equal to the value requesting the READY Timer 
function to be deactivated. 

Regardless of whether or not a timer value has been received by the network in the ATTACH REQUEST or 
ROUTING AREA UPDATE REQUEST messages, the network may include a timer value for the READY timer 
(different or not from the default value) into the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT 
messages, respectively. If the READY Timer value was included, it shall be applied for the GMM context by the 
network and by the MS. 

When the MS proposes a READY Timer value and the Network does not include any READY Timer Value in 
its answer, then the value proposed by the MS shall be applied for the GMM context by the Network and by the 
MS. 

- When neither the MS nor the Network proposes a READY Timer value into the ATTACH REQUEST/ ATTACH 
ACCEPT or ROUTING AREA UPDATE REQUEST/ROUTING AREA UPDATE ACCEPT message, then the 
default value shall be used. 

If the negotiated READY timer value indicates that the ready timer function is deactivated, the READY timer shall 
always run without expiry. If the negotiated READY timer value indicates that the ready timer function is deactivated, 
and within the same procedure the network indicates "force to standby" with the "force to standby" information 
element, the READY timer shall always run without expiry. If the negotiated READY timer value is set to zero, the 
READY timer shall be stopped immediately. 

To account for the LLC frame uplink transmission delay, the READY timer value should be slightly shorter in the 
network than in the MS. This is a network implementation issue. 

If a new READY timer value is negotiated, the MS shall upon the reception of the ATTACH ACCEPT or ROUTING 
AREA UPDATE ACCEPT message perform an initial cell update (either by transmitting a LLC frame or, if required, a 
ATTACH COMPLETE or ROUTING AREA UPDATE COMPLETE message), in order to apply the new READY 
timer value immediately. If both the network and the MS support the Cell Notification, the initial cell update shall use 
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any LLC frame except the LLC NULL frame. If the new READY timer value is set to zero or if the network indicates 
"force to standby" with the "force to standby" IE, the initial cell update should not be done. 

4.7.2.1 .2 Handling of READY timer in lu mode (lu mode only) 

The READY timer is not applicable for lu mode. 

An MS may indicate a READY timer value to the network in the ATTACH REQUEST and the ROUTING AREA 
UPDATE REQUEST messages. 

If a READY timer value is received by an MS capable of both lu mode and A/Gb mode in the ATTACH ACCEPT or 
the ROUTING AREA UPDATE ACCEPT messages, then the received value shall be stored by the MS in order to be 
used at an intersystem change from lu mode to A/Gb mode. 

4.7.2.2 Periodic routing area updating 

Periodic routing area updating is used to periodically notify the availability of the MS to the network. The procedure is 
controlled in the MS by the periodic RA update timer, T3312. The value of timer T3312 is sent by the network to the 
MS in the messages ATTACH ACCEPT and ROUTING AREA UPDATE ACCEPT. The value of the timer T3312 
shall be unique within a RA. 

If the T33 12 received by the MS in A/Gb mode or received in lu mode in a message with integrity protection contains 
an indication that the timer is deactivated or the timer value is zero, then the periodic routing area update timer is 
deactivated and the MS shall not perform periodic routing area updating. 

In lu mode, if the value of timer T33 12 is received in a message without integrity protection and the indicated value is 
larger than the last received value, or the indicated value is "deactivated" or zero, the MS shall use the last received 
value. 

In A/Gb mode, the timer T3312 is reset and started with its initial value, when the READY timer is stopped or expires. 
The timer T3312 is stopped and shall be set to its initial value for the next start when the READY timer is started. If 
after a READY timer negotiation the READY timer value is set to zero, timer T3312 is reset and started with its initial 
value. If the initial READY timer value is zero, the timer T3312 is reset and started with its initial value, when the 
ROUTING AREA UPDATE REQUEST message is transmitted. 

In lu mode, the timer T3312 is reset and started with its initial value, when the MS goes from PMM-CONNECTED to 
PMM-IDLE mode. The timer T3312 is stopped when the MS enters PMM-CONNECTED mode. 

If the MS is attached for emergency bearer services, when timer T3312 expires, the MS shall not initiate a periodic 
RAU procedure, but shall locally detach from the network. 

If the MS is not attached for emergency bearer services, when timer T33 12 expires, the periodic routing area updating 
procedure shall be started and the timer shall be set to its initial value for the next start. 

If the MS is in other state than GMM-REGISTERED.NORMAL-SERVICE when the timer expires the periodic routing 
area updating procedure is delayed until the MS returns to GMM-REGISTERED.NORMAL-SERVICE. 

In A/Gb mode, if the MS in MS operation mode B is in the state GMM-REGISTERED.SUSPENDED when the timer 
expires the periodic routing area updating procedure is delayed until the state is left. 

If ISR is activated, the MS shall keep both the periodic tracking area update timer (timer T3412) and the periodic 
routeing area update timer (timer T3312). The two separate timers run in the MS for updating MME and SGSN 
independently. If the periodic routeing area update timer expires and the timer T3346 is running, the MS shall start the 
GERAN/UTRAN Deactivate ISR timer T3323. If the periodic routeing area update timer expires and the MS is in state 
GMM-REGISTERED.NO-CELL-AVAILABLE, the MS shall start the GERAN/UTRAN Deactivate ISR timer T3323. 
The MS shall initiate the routeing area updating procedure and stop the timer T3323 when the MS enters the state 
GMM-REGISTERED.NORMAL-SERVICE before timer T3323 expires. After expiry of timer T3323 the MS shall 
deactivate ISR by setting its TIN to "GUTI". 

If the GERAN/UTRAN Deactivate ISR timer T3323 expires the MS shall memorize that it has to initiate a routing area 
updating procedure when it returns to state GMM-REGISTERED.NORMAL-SERVICE and the timer T3346 is not 
running. 

The network supervises the periodic routing area updating procedure by means of the Mobile Reachable timer. 
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If the MS is not attached for emergency bearer services, the Mobile Reachable timer shall be longer than the periodic 
RA update timer T3312. In this case, by default, the Mobile Reachable timer is 4 minutes greater than the periodic RA 
update timer. If the network includes T3312 extended value IE in the ATTACH ACCEPT message or ROUTING 
AREA UPDATE ACCEPT message, the network shall use T3312 extended value IE as the value of timer T3312. 

If ISR is not activated, when the Mobile Reachable timer expires, typically the network stops sending paging messages 
to the mobile and may take other appropriate actions. 

If the MS is attached for emergency bearer services, the SGSN shall set the mobile reachable timer with a value equal to 
T3312. When the mobile reachable timer expires, the SGSN shall locally detach the MS. 

In A/Gb mode, the Mobile Reachable timer is reset and started with the value as indicated above, when the READY 
timer is stopped or expires. The Mobile Reachable timer is stopped when the READY timer is started. 

In A/Gb mode, if after a READY timer negotiation the READY timer value is set to zero the Mobile Reachable timer is 
reset and started with its initial value. If the initial READY timer value is zero, the Mobile Reachable is reset and 
started with its initial value, when the ROUTING AREA UPDATE REQUEST message is received. 

In lu mode, the Mobile Reachable timer is reset and started with the value as indicated above, when the MS goes from 
PMM-CONNECTED to PMM-IDLE mode. The Mobile Reachable timer is stopped when the MS enters PMM- 
CONNECTED mode. 

If ISR is activated, upon expiry of the Mobile Reachable timer the network shall start the Implicit Detach timer. By 
default, the Implicit Detach timer is 4 minutes greater than timer T3323. If the Implicit Detach timer expires before the 
MS contacts the network, the network shall implicitly detach the MS and deactivate ISR. 

If ISR is not activated, upon expiry of the Mobile Reachable timer the network may start the Implicit Detach timer. The 
value of the Implicit Detach timer is network dependent. If the Implicit Detach timer expires before the MS contacts the 
network, the network shall implicitly detach the MS. 

If the SGSN includes timer T3346 in the ROUTING AREA UPDATE REJECT message or the SERVICE REJECT 
message and timer T3346 is greater than timer T3312, the SGSN sets the mobile reachable timer and the implicit detach 
timer such that the sum of the timer values is greater than timer T3346. 

If the MS is both IMSI attached for GPRS and non-GPRS services, and if the MS lost coverage of the registered PLMN 
and timer T3312 expires or timer T3323 expires, then: 

a) if the MS returns to coverage in a cell that supports GPRS and that indicates that the network is in network 
operation mode I, then the MS shall either perform the combined routing area update procedure indicating 
"combined RA/LA updating with IMSI attach"; or 

b) if the MS returns to coverage in a cell in the same RA that supports GPRS and that indicates that the network is 
in network operation mode II or III, then the MS shall perform the periodic routing area updating procedure 
indicating "Periodic updating"; or 

c) if the MS was both IMSI attached for GPRS and non-GPRS services in network operation mode I and the MS 
returns to coverage in a cell in the same LA that does not support GPRS, then the MS shall perform the periodic 
location updating procedure. In addition, the MS shall perform a combined routing area update procedure 
indicating "combined RA/LA updating with IMSI attach" when the MS enters a cell that supports GPRS and that 
indicates that the network is in network operation mode I; or 

d) if the MS returns to coverage in a new RA the description given in subclause 4.7.5 applies. 

If this subclause specifies that the MS shall perform a periodic routing area updating procedure, but subclause 4.7.5 
specifies the MS shall perform a normal or combined routing area updating procedure, the description in 
subclause 4.7.5 takes precedence. 

If the MS is both IMSI attached for GPRS and non-GPRS services in a network that operates in network operation 
mode I, and if the MS has camped on a cell that does not support GPRS, and timer T3312 expires or timer T3323 
expires, then the MS shall start an MM location updating procedure. In addition, the MS shall perform a combined 
routing area update procedure indicating "combined RA/LA updating with IMSI attach" when the MS enters a cell that 
supports GPRS and indicates that the network is in operation mode I. 
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If timer T3312 expires or timer T3323 expires during an ongoing CS connection, then a MS operating in MS operation 
mode B shall treat the expiry of T3312 when the MM state MM-IDLE is entered, analogous to the descriptions for the 
cases when the timer expires out of coverage or in a cell that does not support GPRS. 

In A/Gb mode, timer T3312 and timer T3323 shall not be stopped when a GPRS MS enters state GMM- 
REGISTERED.SUSPENDED. 

4.7.2.3 PMM-IDLE mode and PMM-CONNECTED mode (lu mode only) 

An MS shall enter PMM-CONNECTED mode when a PS signalling connection for packet switched domain is 
established between the MS and the network. The MS shall not perform periodic routing area update in PMM- 
CONNECTED mode. 

An MS shall enter PMM-IDLE mode when the PS signalling connection for packet switched domain between the MS 
and the network has been released. The MS shall perform periodic routing area update in PMM-IDLE mode. 

4.7.2.4 Handling of Force to standby \n lu mode (lu mode only) 

Force to standby is not applicable for lu mode. 

The network shall always indicate Force to standby not indicated in the Force to standby information element. 

The Force to standby information element shall be ignored by the MS. 

4.7.2.5 RA Update procedure for Signalling Connection Re-establishment (lu mode 
only) 

When the MS receives an indication from the lower layers that the RRC connection has been released with cause 
"Directed signalHng connection re-establishment", see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111], then the MS 
shall enter PMM-IDLE mode and initiate immediately a normal routing area update procedure (the use of normal or 
combined procedure depends on the network operation mode in the current serving cell) regardless whether the routing 
area has been changed since the last update or not. This routing area update procedure shall also be performed or 
continued if the MS has performed an inter-system change towards GSM, irrespective whether the READY timer is 
running or the MS is in PMM-IDLE or PMM-CONNECTED mode. 

4.7.2.6 Cell Update triggered by low layers 

A Cell Update may be requested by the low layers, see 3GPP TS 44.060 [76]. In this case the Cell Update shall be 
performed even if the READY timer is not running. If both the network and the MS support the Cell Notification, then 
the MS shall use the LLC NULL frame to perform the Cell Update. 



4.7.3 GPRS attach procedure 

The GPRS attach procedure is used for the following purposes: 

- normal GPRS attach, performed by the MS to IMSI attach for GPRS services only. The normal GPRS attach 
procedure shall be used: 

- by GPRS MSs in MS operation mode C, independent of the network operation mode; 

- by GPRS MSs in MS operation modes A or B if the network operates in network operation mode II or III; 
and 

by GPRS MSs in MS operation mode A, independent of the network operation mode, if a circuit-switched 
transaction is ongoing; 

combined GPRS attach procedure, used by GPRS MSs in MS operation modes A or B to attach the IMSI for 
GPRS and non-GPRS services provided that the network operates in network operation mode I. 
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GPRS attach for emergency bearer services, performed by the MS to IMSI or IMEI attach to emergency bearer 
services. 

With a successful GPRS attach procedure a GMM context is established. 

When the timer T3346 is running, MS is allowed to initiate an attach procedure if: 

the MS is accessing the network with ACl 1-15; or 

the MS is attaching for emergency bearer services. 

An eCall only mobile station shall not perform a normal or combined GPRS attach procedure. 

Subclause 4.7.3.1 describes the GPRS attach procedure to attach the IMSI only for GPRS services. The combined 
GPRS attach procedure used to attach the IMSI for both GPRS and non-GPRS services is described in 
subclause 4.7.3.2. GPRS attach for emergency bearer services is described as part of subclause 4.7.3.1. 

If an IMSI attach for non-GPRS services is requested and a GMM context exists, the routing area updating procedure 
shall be used as described in subclause 4.7.5.2. 

To limit the number of subsequently rejected attach attempts, a GPRS attach attempt counter is introduced. The GPRS 
attach attempt counter shall be incremented as specified in subclause 4.7.3.1.5. Depending on the value of the GPRS 
attach attempt counter, specific actions shall be performed. The GPRS attach attempt counter shall be reset when: 

the MS is powered on; 

- a SIM/USIM is inserted; 

a GPRS attach procedure is successfully completed; 

a combined GPRS attach procedure is completed for GPRS services only with cause #2, #16, #17 or #22; 

- a GPRS attach procedure is completed with cause #11, #12, #13, #14 ,#15 or #25; 

a network initiated detach procedure is completed with cause #11, #12, #13, #14, #15 or #25; 

and additionally when the MS is in substate ATTEMPTING-TO-ATTACH: 

expiry of timer T3302; 

a new routing area is entered; 

an attach is triggered by CM sublayer requests; 

timer T3346 is started. 

The mobile equipment shall contain a list of "forbidden location areas for roaming", as well as a list of "forbidden 
location areas for regional provision of service". The handling of these lists is described in subclause 4.4.1; the same 
lists are used by GMM and MM procedures. 

The Mobile Equipment shall contain a list of "equivalent PLMNs". The handling of this list is described in 
subclause 4.4.1, the same list is used by GMM and MM procedures. 

In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The MS 
shall construct the Routing Area Identification of the cell from this chosen PLMN identity, and the LAC and the RAC 
received on the BCCH. The chosen PLMN identity shall be indicated to the UTRAN in the RRC INITIAL DIRECT 
TRANSFER message (see 3GPP TS 25.331 [23c]). Whenever an ATTACH REJECT message with the cause "PLMN 
not allowed" is received by the MS, the chosen PLMN indentity shall be stored in the "forbidden PLMN list". 
Whenever an ATTACH REJECT message is received by the MS with the cause "Roaming not allowed in this location 
area", "Location Area not allowed", or "No suitable cells in Location Area", the LAI that is part of the constructed RAI 
shall be stored in the suitable list. 

The network informs the MS about the support of specific features, such as LCS-MOLR, MBMS, IMS voice over PS 
session, or emergency bearer services in lu mode in the "Network feature support" Information Element. The 
information is either explicitly given by sending the "Network feature support" IE or implicitly by not sending it. The 
handling in the network is described in subclause 9.4.2.9. The MS may use the support indications for LCS-MOLR and 
MBMS to inform the user about the availability of the appropriate services. The MS shall not request any of these two 
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services, if the service has not been indicated as available. The indication for MBMS is defined in subclause "MBMS 
feature support indication" in 3GPP TS 23.246 [106]. In an MS with IMS voice over PS capability, the IMS voice over 
PS session indicator and the emergency bearer services indicator shall be provided to the upper layers. The upper layers 
take the IMS voice over PS session indicator into account as specified in 3GPP TS 23.221 [131], subclause 7.2a and 
subclause 7.2b, when selecting the access domain for voice sessions or calls in lu mode. When initiating an emergency 
call in lu mode, the upper layers also take the emergency bearer services indicator into account for the access domain 
selection. 

4.7.3.1 GPRS attach procedure for GPRS services 

The GPRS attach procedure is a GMM procedure used by GPRS MSs to IMSI attach for GPRS services. The procedure 
is also used by GPRS MSs to IMSI or IMEI attach for emergency bearer services. 

The attach type information element shall indicate "GPRS attach". For an MS attaching for emergency bearer services 
the attach type information element shall indicate "Emergency attach". 

4.7.3.1 .1 GPRS attach procedure initiation 

In state GMM-DEREGISTERED, the MS initiates the GPRS attach procedure by sending an ATTACH REQUEST 
message to the network, starts timer T3310 and enters state GMM-REGISTERED-INITIATED. 

If the MS is configured for "Attach WithlMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and the 
selected PLMN is neither the registered PLMN nor in the list of equivalent PLMNs, the MS shall include the IMSI in 
the Mobile identity IE in the ATTACH REQUEST message. 

For all other cases, the MS shall handle the Mobile identity IE in the ATTACH REQUEST message as follows: 

If the MS does not support SI mode: 

the MS capable of both lu mode and A/Gb mode or only of A/Gb mode shall include a valid P-TMSI, if any is 
available, the P-TMSI signature associated with the P-TMSI and the routing area identity associated with the P- 
TMSI in the ATTACH REQUEST message. In addition, the MS shall include P-TMSI type IE with P-TMSI 
type set to "native P-TMSI". If there is no valid P-TMSI available, the IMSI shall be included instead of the P- 
TMSI and P-TMSI signature. 

If the MS supports SI mode: 

- if the TIN indicates "GUTI" and the MS holds a valid GUTI, the MS shall map the GUTI into the Mobile 
identity IE, P-TMSI signature IE and Old routing area identification IE. The MS shall also include P-TMSI type 
IE with P-TMSI type set to "mapped P-TMSI". Additionally, if the MS holds a vaHd P-TMSI and RAI, the MS 
shall indicate the P-TMSI in the Additional mobile identity IE and the RAI in the Additional old routing area 
identification IE. 

NOTE: The mapping of the GUTI to the P-TMSI, P-TMSI signature and RAI is specified in 3GPP TS 23.003 [4]. 

- If the TIN indicates "P-TMSI" or "RAT-related TMSI" and the MS holds a valid P-TMSI and a RAI, the MS 
shall indicate the P-TMSI in the Mobile identity IE and the RAI in the Old routing area identification IE. The 
MS shall also include P-TMSI type IE with P-TMSI type set to "native P-TMSI". If a P-TMSI signature is 
associated with the P-TMSI, the MS shall include it in the Old P-TMSI signature IE. 

- If the TIN is deleted and 

- the MS holds a valid P-TMSI and a RAI, the MS shall indicate the P-TMSI in the Mobile identity IE and the 
RAI in the Old routing area identification IE. The MS shall also include P-TMSI type IE with P-TMSI type 
set to "native P-TMSI". If a P-TMSI signature is associated with the P-TMSI, the MS shall include it in the 
Old P-TMSI signature IE; or 

- the MS does not hold a valid P-TMSI and RAI, but holds a valid GUTI, the MS shall map the GUTI into the 
Mobile identity IE, P-TMSI signature IE and Old routing area identification IE. The MS shall also include P- 
TMSI type IE with P-TMSI type set to "mapped P-TMSI"; or 

- the MS does not hold a valid P-TMSI, RAI or GUTI, the MS shall include the IMSI in the Mobile identity IE. 

- Otherwise the MS shall include the IMSI in the Mobile identity IE. 
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In the cases when the MS maps a GUTI into the Mobile identity IE, P-TMSI signature IE and Old routing area 
identification IE, then: 

If a current EPS security exists, the P-TMSI signature shall include a truncated NAS token as specified in 
3GPP TS 33.401 [119]. In the GPRS ciphering key sequence number IE, the MS shall indicate the value of the 
eKSI associated with the current EPS security context. The MS shall derive CK' and IK' from the Kasme and the 
NAS uplink COUNT value corresponding to the NAS token derived and handle the START value as specified in 
3GPP TS 25.331 [23c]. Then, the MS shall store the mapped UMTS security context replacing the established 
UMTS security context for the PS domain. 

If a current EPS security does not exist, the MS shall set the truncated NAS token included in the P-TMSI 
signature to all zeros and the GPRS ciphering key sequence number to "No key is available". 

If the MS is attaching for emergency bearer services and does not hold a valid GUTI, Mobile identity as described 
above, the IMEI shall be included in the Mobile identity IE. 

The MS shall also indicate within the DRX parameters whether it supports the split pg cycle option on CCCH. The 
optional support of the split pg cycle on CCCH by the network is indicated in SI13 or PSIl. Split pg cycle on CCCH is 
applied by both the network and the MS when the split pg cycle option is supported by both (see 3GPP TS 45.002 [32]). 

In lu mode, if the MS wishes to prolong the established PS signalling connection after the GPRS attach procedure (for 
example, the MS has any CM application request pending), it may set a follow-on request pending indicator on (see 
subclause 4.7.13). 

An MS attaching for emergency bearer services shall set the follow-on request pending indicator. 

4.7.3.1 .2 GMM common procedure initiation 

If the network receives an ATTACH REQUEST message containing the P-TMSI type IE and the Mobile identity IE 
with type of identity indicating "TMSI/P-TMSI/M-TMSI", and the network does not follow the use of the most 
significant bit of the LAC as specified in 3GPP TS 23.003 [10] subclause 2.8.2.2.2, the network shall use the P-TMSI 
type IE to determine whether the mobile identity included in the Mobile identity IE is a native P-TMSI or a mapped 
P-TMSI. 

The network may initiate GMM common procedures, e.g. the GMM identification and GMM authentication and 
ciphering procedure, depending on the received information such as IMSI, CKSN, old RAJ, P-TMSI and P-TMSI 

signature. 

4.7.3.1 .3 GPRS attach accepted by the network 

During an attach for emergency bearer services, if not restricted by local regulations, the network shall not check for 
mobility and access restrictions, regional restrictions, subscription restrictions, or perform CSG access control when 
processing the ATTACH REQUEST message. The network shall not apply subscribed APN based congestion control 
during an attach procedure for emergency bearer services. 

If the GPRS attach request is accepted by the network, an ATTACH ACCEPT message is sent to the MS. 

The P-TMSI reallocation may be part of the GPRS attach procedure. When the ATTACH REQUEST includes the IMSI 
or IMEI, the SGSN shall allocate the P-TMSI. The P-TMSI that shall be allocated is then included in the ATTACH 
ACCEPT message together with the routing area identifier. The network shall, in this case, change to state GMM- 
COMMON-PROCEDURE-INITIATED and shall start timer T3350 as described in subclause 4.7.6. Furthermore, the 
network may assign a P-TMSI signature for the GMM context which is then also included in the ATTACH ACCEPT 
message. If the LAI or PLMN identity that has been transmitted in the ATTACH ACCEPT message is a member of any 
of the "forbidden" lists, any such entry shall be deleted. If the attach procedure is for emergency bearer services, the 
"forbidden" lists shall remain unchanged. Additionally, the network shall include the radio priority level to be used by 
the MS for mobile originated SMS transfer in the ATTACH ACCEPT message. In a shared network, if the MS is 
supporting network sharing, the network shall indicate the PLMN identity of the CN operator that has accepted the 
GPRS attach request in the RAI contained in the ATTACH ACCEPT message; if the MS is not supporting network 
sharing, the network shall indicate the PLMN identity of the common PLMN (see 3GPP TS 23.251 [109]). 

In a multi-operator core network (MOCN) with common GERAN, the network shall indicate in the RAI the common 
PLMN identity (see 3GPP TS 23.251 [109]). 
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If the MS has indicated in the ATTACH REQUEST message that it supports PS inter-RAT handover from GERAN to 
UTRAN lu mode, the network may include in the ATTACH ACCEPT message a request to provide the Inter RAT 
information container. 

If the MS has indicated in the ATTACH REQUEST message that it supports PS inter-RAT HO from GERAN to E- 
UTRAN, the network may include in the ATTACH ACCEPT message a request to provide the E-UTRAN inter RAT 
information container. 

If the MS has included the MS network capability IE or the UE network capability IE or both in the ATTACH 
REQUEST message, the network shall store all octets received from the MS, up to the maximum length defined for the 
respective information element. 

NOTE 1: This information is forwarded to the new SGSN during inter-SGSN handover or to the new MME during 
intersystem handover to SI mode. 

If the DRX parameter was included in the DRX Parameter IE in the ATTACH REQUEST message, the network shall 
replace any stored DRX parameter with the received parameter and use it for the downlink transfer of signalling and 
user data. 

In A/Gb mode, the Cell Notification information element shall be included in the ATTACH ACCEPT message by the 
network which indicates that the Cell Notification is supported by the network. 

In lu mode, the network should prolong the PS signalling connection if the mobile station has indicated a follow-on 
request pending in ATTACH REQUEST. The network may also prolong the PS signalling connection without any 
indication from the mobile terminal. 

The MS, receiving an ATTACH ACCEPT message, stores the received routing area identification, stops timer T3310, 
reset the GPRS attach attempt counter, reset the routing area updating attempt counter, enters state GMM- 
REGISTERED and sets the GPRS update status to GUI UPDATED. 

If the message contains a P-TMSI, the MS shall use this P-TMSI as the new temporary identity for GPRS services. In 
this case, an ATTACH COMPLETE message is returned to the network. The MS shall delete its old P-TMSI and shall 
store the new one. If no P-TMSI has been included by the network in the ATTACH ACCEPT message, the old P-TMSI, 
if any available, shall be kept. 

If the message contains a P-TMSI signature, the MS shall use this P-TMSI signature as the new temporary signature for 
the GMM context. The MS shall delete its old P-TMSI signature, if any is available, and shall store the new one. If the 
message contains no P-TMSI signature, the old P-TMSI signature, if available, shall be deleted. 

Upon receiving the ATTACH ACCEPT message an MS supporting SI mode shall set the TIN to "P-TMSI". 

If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover 
information or both, the MS shall return an ATTACH COMPLETE message including the Inter RAT handover 
information IE or the E-UTRAN inter RAT handover information IE or both to the network. 

The network may also send a list of "equivalent PLMNs" in the ATTACH ACCEPT message. Each entry of the list 
contains a PLMN code (MCCh-MNC). The mobile station shall store the list, as provided by the network, and if the 
GPRS attach procedure is not for emergency bearer services, any PLMN code that is already in the "forbidden PLMN" 
list shall be removed from the "equivalent PLMNs" list before it is stored by the mobile station. In addition the mobile 
station shall add to the stored list the PLMN code of the registered PLMN that sent the list. All PLMNs in the stored Ust 
shall be regarded as equivalent to each other for PLMN selection, cell selection/re-selection and handover. The stored 
list in the mobile station shall be replaced on each occurrence of the ATTACH ACCEPT message. If no list is contained 
in the message, then the stored list in the mobile station shall be deleted. An MS attached for emergency bearer services 
shall delete the stored list when the MS enters the state GMM-DEREGISTERED. The list shall be stored in the mobile 
station while switched off so that it can be used for PLMN selection after switch on. 

If the ATTACH ACCEPT message contains T3312 extended value IE, then the MS shall use the T3312 extended value 
IE as periodic routing area update timer (T3312). If the ATTACH ACCEPT message does not contain T3312 extended 
value IE, then the MS shall use the T3312 value IE as periodic routing area update timer (T3312). 

In lu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has 
indicated "follow-on request pending" in ATTACH REQUEST message) the network shall indicate the "follow-on 
proceed" in the ATTACH ACCEPT message. If the network wishes to release the PS signalling connection, the 
network shall indicate "no follow-on proceed" in the ATTACH ACCEPT message. 
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After that in lu mode, the mobile station shall act according to the follow-on proceed flag included in the Attach result 
information element in the ATTACH ACCEPT message (see subclause 4.7.13). 

In A/Gb mode, if the ATTACH ACCEPT message contains the Cell Notification information element, then the MS 
shall start to use the LLC NULL frame to perform cell updates. The network receiving an ATTACH COMPLETE 
message stops timer T3350, changes to GMM-REGISTERED state and considers the P-TMSI sent in the ATTACH 
ACCEPT message as valid. 

The network may also send a list of local emergency numbers in the ATTACH ACCEPT, by including the Emergency 
Number List IE. The mobile equipment shall store the list, as provided by the network, except that any emergency 
number that is already stored in the SIM/USIM shall be removed from the list before it is stored by the mobile 
equipment. If there are no emergency numbers stored on the SIM/USIM, then before storing the received list the mobile 
equipment shall remove from it any emergency number stored permanently in the ME for use in this case (see 3GPP TS 
22.101 [8]). The list stored in the mobile equipment shall be replaced on each receipt of a new Emergency Number List 
IE. 

The emergency number(s) received in the Emergency Number List IE are valid only in networks with the same MCC as 
in the cell on which this IE is received. If no list is contained in the ATTACH ACCEPT message, then the stored list in 
the mobile equipment shall be kept, except if the mobile equipment has successfully registered to a PLMN with an 
MCC different from that of the last registered PLMN. 

The mobile equipment shall use the stored list of emergency numbers received from the network in addition to the 
emergency numbers stored on the SIM/USIM or ME to detect that the number dialled is an emergency number. 

NOTE 2: The mobile equipment may use the emergency numbers list to assist the end user in determining whether 
the dialled number is intended for an emergency service or for another destination, e.g. a local directory 
service. The possible interactions with the end user are implementation specific. 

The list of emergency numbers shall be deleted at switch off and removal of the SIM/USIM. The mobile equipment 
shall be able to store up to ten local emergency numbers received from the network. 

If the MS has initiated the attach procedure due to manual CSG selection and receives an ATTACH ACCEPT message, 
and the MS sent the ATTACH REQUEST message in a CSG cell, the MS shall check if the CSG ID and associated 
PLMN identity of the cell are contained in the Allowed CSG list. If not, the MS shall add that CSG ID and associated 
PLMN identity to the Allowed CSG list and the MS may add the HNB Name (if provided by lower layers) to the 
Allowed CSG list if the HNB Name is present in neither the Operator CSG list nor the Allowed CSG list. 

4.7.3.1 .4 GPRS attach not accepted by the network 

If the attach request cannot be accepted by the network, an ATTACH REJECT message is transferred to the MS. The 
MS receiving the ATTACH REJECT message, stops timer T3310 and for all causes except #12, #14, #15, #22 and #25 
deletes the list of "equivalent PLMNs". 

If the attach request is rejected due to NAS level mobility management congestion control, the network shall set the 
GMM cause value to #22 "congestion" and assign a back-off timer T3346. 

The MS shall then take one of the following actions depending upon the reject cause: 

# 3 (Illegal MS); 

# 6 (Illegal ME); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The new GMM state is GMM-DEREGISTERED. The SIM/USIM shall be considered as invalid for 
GPRS services until switching off or the SIM/USIM is removed. 

If the MS is IMSI attached, the MS shall in addition set the update status to U3 ROAMING NOT ALLOWED, 
shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS operation mode A 
and an RR connection exists, the MS shall abort the RR connection, unless an emergency call is ongoing. The 
SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the SIM/USIM is 
removed. 
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If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAX Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
attach procedure is rejected with the EMM cause with the same value. 

# 7 (GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM 
is removed. The new state is GMM-DEREGISTERED. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
attach procedure is rejected with the EMM cause with the same value. 

# 8 (GPRS services and non-GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The new GMM state is GMM-DEREGISTERED. 

The MS shall set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI and 
ciphering key sequence number. If the MS is operating in MS operation mode A and an RR connection exists, 
the MS shall abort the RR connection, unless an emergency call is ongoing. The SIM/USIM shall be considered 
as invalid for GPRS and non-GPRS services until switching off or the SIM/USIM is removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
attach procedure is rejected with the EMM cause with the same value. 

# 1 1 (PLMN not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and shall change to state GMM- 
DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMN list". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [14]. 

An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when attach procedure is rejected with the EMM cause with the same value. 

# 12 (Location area not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE. 

The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service". 
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The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE 1 : The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the attach procedure is rejected with the EMM cause with the same value. 

#13 (Roaming not allowed in this location area); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE or optionally to GMM-DEREGISTERED.PLMN-SEARCH. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [ 14] . 

An MS in GAN mode shall request a PLMN Hst in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the attach procedure is rejected with the EMM cause with the same value. 

# 14 (GPRS services not allowed in this PLMN); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) , shall reset the GPRS attach attempt counter and shall change to state GMM- 
DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. A GPRS MS operating 
in MS operation mode C shall perform a PLMN selection instead of a cell selection. 

A GPRS MS operating in MS operation mode A or B in network operation mode II or III, is still IMSI attached 
for CS services in the network. 

As an implementation option, a GPRS MS operating in operation mode A or B may perform the following 
additional action. If no RR connection exists the MS may perform the action immediately. If the MS is operating 
in MS operation mode A and an RR connection exists, the MS may only perform the action when the RR 
connection is subsequently released: 

- The MS may perform a PLMN selection according to 3GPP TS 23. 122 [14]. 
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If an MS in GAN mode performs a PLMN selection, it shall request a PLMN list in GAN (see 

3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23.122 [14]. 

The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause 
is: 

On the "User Controlled PLMN Selector with Access Technology " list or, 

On the "Operator Controlled PLMN Selector with Access Technology " list or, 

A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the attach procedure is rejected with the EMM cause with the same value. 

#15 (No Suitable Cells In Location Area); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN 
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121]. 

NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the attach procedure is rejected with the EMM cause with the same value. 

# 22 (Congestion); 

If the T3346 value IE is present in the ATTACH REJECT message and the value indicates that this timer is 
neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be considered as an 
abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.3.1.5. 

The MS shall abort the attach procedure, reset the attach attempt counter, set the GPRS update status to GU2 
NOT UPDATED and enter state GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH. 

The MS shall stop timer T3346 if it is running. 

If the ATTACH REJECT message is integrity protected, the MS shall start timer T3346 with the value provided 
in the T3346 value IE. 

If the ATTACH REJECT message is not integrity protected, the MS shall start timer T3346 with a random value 
from the default range specified in table 1 1.3a. 

The MS stays in the current serving cell and applies the normal cell reselection process. The attach procedure is 
started if still needed when timer T3346 expires or is stopped. 

# 25 (Not authorized for this CSG); 
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Cause #25 is only applicable in UTRAN lu mode and when received from a CSG cell. Other cases are 
considered as abnormal cases and the specification of the mobile station behaviour is given in 
subclause 4.7.3.1.5. 

If the ATTACH REJECT message with cause #25 was received without integrity protection, then the MS shall 
discard the message. 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), reset the GPRS attach attempt counter and enter the state GMM- 
DEREGISTERED.LIMITED-SERVICE. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST 
message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry corresponding to 
this CSG ID and associated PLMN identity from the Allowed CSG Ust. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST 
message are contained in the Operator CSG list stored in the MS, the MS shall proceed as specified in 
3GPP TS 23.122 [14] subclause 3.1A. 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the attach procedure is rejected with the EMM cause with the same value. 

Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is specified in 
subclause 4.7.3.1.5. 

4.7.3.1 .4a GPRS attach for emergency bearer services not accepted by the network 

(UTRAN lu mode only) 

If the attach request for emergency bearer services cannot be accepted by the network, an ATTACH REJECT message 
is transferred to the MS. The ATTACH REJECT message includes GMM cause #5 'TMEI not accepted" or one of the 
GMM cause values as described in subclause 4.7.3.1.4. 

NOTE: If GMM cause #1 1 is sent to a MS of a roaming subscriber attaching for emergency bearer services and 
the MS is in automatic network selection mode, it cannot obtain normal service provided by this PLMN. 

Upon receiving the ATTACH REJECT message including GMM cause #5, the MS shall enter the state GMM- 
DEREGISTERED.NO-IMSI. 

Upon receiving the ATTACH REJECT message including one of the other GMM cause values, the MS shall perform 
the actions as described in subclause 4.7.3.1.4 with the following addition: upon request from upper layers a CS voice 
capable MS may establish the emergency call using the CS domain. 

In a shared network, upon receiving the ATTACH REJECT message, the MS shall perform the actions as described in 
subclause 4.7.3.1.4 with the following additions: 

a) upon request from upper layers a CS voice capable MS may attempt the emergency call using the CS domain; or 

b) an MS may try the attach for emergency bearer services to another PLMN in the shared network. 

If options a) and b) above are either not applicable or one or both of them have failed an MS may attempt the 
emergency call using other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [13D] 
that can result in the emergency call being attempted to another IP-CAN. 
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4.7.3.1 .4b Attach for initiating a PDN connection for emergency bearer services not 

accepted by the network (UTRAN lu mode only) 

If the network cannot accept the attach request for initiating a PDN connection for emergency bearer services with 
attach type not set to "emergency attach", the MS shall perform the procedures as described in subclause 4.7.3.1.4. Then 
if the MS is in the same selected PLMN where the last attach request was attempted, the MS shall: 

a) inform the upper layers. This could result in the MS attempting a CS emergency call (if not already attempted in 
the CS domain) or other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [95] 
that can result in the emergency call being attempted to another IP -CAN; or 

b) attempt GPRS attach for emergency bearer services. 

4.7.3.1 .5 Abnormal cases in the MS 

The following abnormal cases can be identified: 

a) Access barred because of access class control 

The GPRS attach procedure shall not be started. The MS stays in the current serving cell and applies normal cell 
reselection process. The GPRS attach procedure is started as soon as possible, i.e. when access is granted or 
because of a cell change. 

b) Lower layer failure without "Extended wait time" received from lower layers before the ATTACH ACCEPT or 
ATTACH REJECT message is received. 

The procedure shall be aborted and the MS shall proceed as described below, except in the following 
implementation option cases b.l and b.2. 

b. 1) Release of PS signalling connection in lu mode before the completion of the GPRS attach procedure 

If the release of the PS signalling connection occurs before completion of the GPRS attach procedure, then the 
GPRS attach procedure shall be initiated again, if the following conditions apply: 

i) The original GPRS attach procedure was initiated over an existing PS signalling connection; and 

ii) The GPRS attach procedure was not due to timer T3310 expiry; and 

iii) No SECURITY MODE COMMAND message and no Non- Access Startum (NAS) messages relating to 
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the 
ATTACH REQUEST message was transmitted. 

b.2) RR release in lu mode (i.e. RRC connection release) with, for example, cause "Normal", or "User inactivity" 
(see 3GPPTS 25.331 [23c] and 3GPP TS 44.118 [111]) 

The GPRS attach procedure shall be initiated again, if the following conditions apply: 

i) The original GPRS attach procedure was initiated over an existing RRC connection; and 

ii) The GPRS attach procedure was not due to timer T3310 expiry; and 

iii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to 
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the 
ATTACH REQUEST message was transmitted. 

NOTE 1 : The RRC connection release cause that triggers the re-initiation of the GPRS attach procedure is 
implementation specific. 

c) T33 10 time-out 

On the first expiry of the timer, the MS shall reset and restart timer T3310 and shall retransmit the ATTACH 
REQUEST message. This retransmission is repeated four times, i.e. on the fifth expiry of timer T3310, the MS 
shall abort the GPRS attach procedure and, in lu mode, release the PS signalling connection (see 
3GPP TS 25.331 [23c]). The MS shall proceed as described below. 
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d) ATTACH REJECT, other causes than those treated in subclause 4.7.3. 1 .4, and cases of GMM cause #22, if 
considered as abnormal cases according to subclause 4.7.3.1.4 

Upon reception of the cause codes # 95, # 96, # 97, # 99 and # 1 11 the MS should set the GPRS attach attempt 
counter to 5. The MS shall proceed as described below. 

e) Change of cell within the same RA (A/Gb mode only) 

If a cell change occurs within the same RA when the MS is in state GMM-REGISTERED-INITIATED, then the 
cell update procedure shall be performed before completion of the attach procedure. 

f) Change of cell into a new routing area 

If a cell change into a new routing area occurs before an ATTACH ACCEPT or ATTACH REJECT message has 
been received, the GPRS attach procedure shall be aborted and re-initiated immediately. If a routing area border 
is crossed when the ATTACH ACCEPT message is received but before an ATTACH COMPLETE message is 
sent, the GPRS attach procedure shall be aborted and the routing area updating procedure shall be initiated. If a 
P-TMSI was allocated during the GPRS attach procedure, this P-TMSI shall be used in the routing area updating 
procedure. If a P-TMSI signature was allocated together with the P-TMSI during the GPRS attach procedure, 
this P-TMSI signature shall be used in the routing area updating procedure. 

g) Mobile originated detach required 

If the MS is in state GMM-REGISTERED-INITIATED, the GPRS attach procedure shall be aborted and the 
GPRS detach procedure shall be performed (see subclause 4.7.4.1). 

h) Procedure collision 

If the MS receives a DETACH REQUEST message from the network in state GMM-REGISTERED- 
INITIATED with type of detach 're-attach not required, the GPRS detach procedure shall be progressed and the 
GPRS attach procedure shall be aborted. Otherwise the GPRS attach procedure shall be progressed and the 
DETACH REQUEST message shall be ignored. 

i) "Extended wait time" for PS domain from the lower layers 

If the ATTACH REQUEST message contained the NAS signalling low priority indication set to "MS is 
configured for NAS signalling low priority", the MS shall start timer T3346 with the "Extended wait time" 
value. 

In other cases the MS shall ignore the "Extended wait time". 

The MS shall abort the attach procedure, reset the attach attempt counter, stay in the current serving cell, change 
the state to GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH and apply the normal cell reselection 
process. 

The GPRS attach procedure is started, if still necessary, when timer T3346 expires or is stopped. 

j) Timer T3346 is running 

The MS shall not start the GPRS attach procedure unless the MS needs to attach for emergency bearer services. 
The MS stays in the current serving cell and applies normal cell reselection process. The GPRS attach procedure 
is started, if still necessary, when timer T3346 expires or is stopped. 

NOTE 2: It is considered an abnormal case if the MS needs to initiate an attach procedure while timer T3346 is 
running independent on whether timer T3346 was started due to an abnormal case or a non successful 
case. 

In cases b, c and d the MS shall proceed as follows. Timer T3310 shall be stopped if still running. The GPRS attach 
attempt counter shall be incremented. 

If the GPRS attach attempt counter is less than 5: 

- timer T33 1 1 is started and the state is changed to GMM-DEREGISTERED. ATTEMPTING-TO-ATTACH. 

If the GPRS attach attempt counter is greater than or equal to 5: 
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- the MS shall delete any RAI, P-TMSI, P-TMSI signature, list of equivalent PLMNs, and GPRS ciphering key 
sequence number, shall set the GPRS update status to GU2 NOT UPDATED, shall start timer T3302. The state 
is changed to GMM-DEREGISTERED. ATTEMPTING-TO-ATTACH or optionally to GMM- 
DEREGISTERED.PLMN-SEARCH (see subclause 4.2.4.1.2) in order to perform a PLMN selection according 
to 3GPPTS 23.122 [14]. 

- If SI mode is supported by the MS, the MS shall in addition handle the EMM parameters EMM state, EPS 
update status, GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the 
abnormal case when a normal attach procedure fails and the attach attempt counter is equal to 5. 

4.7.3.1 .6 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) Lower layer failure 

If a low layer failure occurs before the message ATTACH COMPLETE has been received from the MS and a 
new P-TMSI (or a new P-TMSI and a new P-TMSI signature) has been assigned, the network shall consider both 
the old and new P-TMSI each with its corresponding P-TMSI-signature as valid until the old P-TMSI can be 
considered as invalid by the network (see subclause 4.7.1.5) and shall not resent the message ATTACH 
ACCEPT. During this period the network may: 

use the identification procedure followed by a P-TMSI reallocation procedure if the old P-TMSI is used by 
the MS in a subsequent message. 

b) Protocol error 

If the ATTACH REQUEST message is received with a protocol error, the network shall return an ATTACH 
REJECT message with one of the following reject causes: 

#96: Mandatory information element error; 

#99: Information element non-existent or not implemented; 

#100: Conditional IE error; 

#111: Protocol error, unspecified. 

c) T3350 time-out 

On the first expiry of the timer, the network shall retransmit the ATTACH ACCEPT message and shall reset and 
restart timer T3350. 

This retransmission is repeated four times, i.e. on the fifth expiry of timer T3350, the GPRS attach procedure 
shall be aborted. If a new P-TMSI or a new P-TMSI together with a new P-TMSI signature were allocated in the 
ATTACH ACCEPT message, the network shall consider both the old and new P-TMSI each together with the 
corresponding P-TMSI signatures as valid until the old P-TMSI can be considered as invalid by the network (see 
subclause 4.7.1.5). During this period the network acts as specified for case a. 

d. 1) ATTACH REQUEST received after the ATTACH ACCEPT message has been sent and before the ATTACH 
COMPLETE message is received 

If one or more of the information elements in the ATTACH REQUEST message differ from the ones received 
within the previous ATTACH REQUEST message, the previously initiated GPRS attach procedure shall be 
aborted if the ATTACH COMPLETE message has not been received and the new GPRS attach procedure shall 
be progressed, or 

If the information elements do not differ, then the ATTACH ACCEPT message shall be resent and the timer 
T3350 shall be restarted if an ATTACH COMPLETE message is expected. In that case, the retransmission 
counter related to T3350 is not incremented. 

d.2) More than one ATTACH REQUEST received and no ATTACH ACCEPT or ATTACH REJECT message 
has been sent 
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If one or more of the information elements in the ATTACH REQUEST message differs from the ones received 
within the previous ATTACH REQUEST message, the previously initiated GPRS attach procedure shall be 
aborted and the new GPRS attach procedure shall be progressed; 

If the information elements do not differ, then the network shall continue with the previous attach procedure and 
shall not treat any further this ATTACH REQUEST message. 

e) ATTACH REQUEST received in state GMM-REGISTERED 

If an ATTACH REQUEST message is received in state GMM-REGISTERED the network may initiate the 
GMM common procedures; if it turned out that the ATTACH REQUEST message was send by an MS that has 
already been attached, the GMM context, PDP contexts and MBMS contexts, if any, are deleted and the new 
ATTACH REQUEST is progressed. 

f) ROUTING AREA UPDATE REQUEST message received before ATTACH COMPLETE message. 

Timer T3350 shall be stopped. The allocated P-TMSI shall be considered as valid and the routing area updating 
procedure shall be progressed as described in subclause 4.7.5. 
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Figure 4.7.3/1 3GPP TS 24.008: GPRS attach procedure and combined GPRS attach procedure 



4.7.3.2 



Combined GPRS attach procedure for GPRS and non-GPRS services 



The combined GPRS attach procedure is a GMM procedure used by a GPRS MS operating in MS operation modes A or 
B for IMSI attach for GPRS and non-GPRS services if the network operates in network operation mode I. 

If a GPRS MS operating in MS operation modes A or B is already attached for non-GPRS services by use of the MM 
specific IMSI attach procedure, but additionally wishes to perform an IMSI attach for GPRS services, the combined 
GPRS attach procedure shall also be used. 

The attach type information element shall indicate "combined GPRS/IMSI attach". In this case, the messages ATTACH 
ACCEPT, ATTACH COMPLETE, and ATTACH REJECT used by the combined GPRS attach procedure carry 
information for both the GPRS and the non-GPRS services. 

A GPRS MS in MS operation mode A shall perform the normal GPRS/IMSI attach procedure during an ongoing 
circuit-switched transaction. 
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4.7.3.2.1 Combined GPRS attach procedure initiation 

If the MS is in GMM state GMM-DEREGISTERED and in MM state MM IDLE, the MS initiates the combined GPRS 
attach procedure by sending an ATTACH REQUEST message to the network, starts timer T3310 and enters state 
GMM-REGISTERED-INITIATED and MM LOCATION UPDATING PENDING. 

The MS shall include a valid P-TMSI, if available, the P-TMSI signature associated with the P-TMSI and the routing 
area identity associated with the P-TMSI in the ATTACH REQUEST message. If there is no valid P-TMSI available, 
the IMSI shall be included instead of the P-TMSI and P-TMSI signature. Furthermore the MS shall include the TMSI 
status IE if no valid TMSI is available. 

If the MS has stored a valid LAI and the MS supports EMM combined procedures, the MS shall include it in the Old 
location area identification IE in the ATTACH REQUEST message. 

In lu mode, if the MS wishes to prolong the established PS signalling connection after the GPRS attach (for example, 
the MS has any CM application request pending), it may set a follow-on request pending indicator on (see 
subclause 4.7.13). 

4.7.3.2.2 GMM Common procedure initiation 

The network may initiate GMM common procedures, e.g. the GMM identification and GMM authentication and 
ciphering procedure, depending on the received information such as IMSI, CKSN, old RAI, P-TMSI and P-TMSI 

signature. 

4.7.3.2.3 Combined GPRS attach accepted by the networl< 

Depending on the value of the attach result IE received in the ATTACH ACCEPT message, two different cases can be 
distinguished: 

Case 1) The attach result IE value indicates "combined GPRS attach": IMSI attach for GPRS and non-GPRS 
services have been successful. 

Case 2) The attach result IE value indicates "GPRS only": IMSI attach for GPRS services has been successful but 
IMSI attach for non-GPRS services has not been successful. 

In lu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has 
indicated "follow-on request pending" in ATTACH REQUEST message) the network shall indicate the "follow-on 
proceed" in the ATTACH ACCEPT message. If the network wishes to release the PS signalling connection, the 
network shall indicate "no follow-on proceed" in the ATTACH ACCEPT message. 

After that in lu mode, the mobile station shall act according to the follow-on proceed flag included in the Attach result 
information element in the ATTACH ACCEPT message (see subclause 4.7.13). 



4.7.3.2.3.1 Combined attach successful for GPRS and non-GPRS services 

The description for IMSI attach for GPRS services as specified in subclause 4.7.3.1.3 shall be followed. In addition, the 
following description for IMSI attach for non-GPRS services applies. 

The TMSI reallocation may be part of the combined GPRS attach procedure. The TMSI allocated is then included in the 
ATTACH ACCEPT message together with the location area identification (LAI). The network shall, in this case, 
change to state GMM-COMMON-PROCEDURE-INITIATED and shall start timer T3350 as described in 
subclause 4.7.6. 

The MS, receiving an ATTACH ACCEPT message, stores the received location area identification, stops timer T3310, 
reset the location update attempt counter and sets the update status to Ul UPDATED. If the message contains an IMSI, 
the mobile station is not allocated any TMSI, and shall delete any TMSI accordingly. If the message contains a TMSI, 
the MS shall use this TMSI as the new temporary identity. The MS shall delete its old TMSI and shall store the new 
TMSI. In this case, an ATTACH COMPLETE message is returned to the network. If neither a TMSI nor an IMSI has 
been included by the network in the ATTACH ACCEPT message, the old TMSI, if any available, shall be kept. The 
new MM state is MM IDLE, the new GMM state is GMM-REGISTERED. 
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If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover 
information or both, the MS shall return an ATTACH COMPLETE message including the Inter RAT handover 
information IE or the E-UTRAN inter RAT handover information IE or both to the network. 

Any timer used for triggering the location update procedure (e.g T3211, T3212) shall be stopped if running. 

The network receiving an ATTACH COMPLETE message stops timer T3350, changes to state GMM-REGISTERED 
and considers the new TMSI as valid. 

4.7.3.2.3.2 Combined attach successful for GPRS services only 

Apart from the actions on the routing area updating attempt counter, the description for IMSI attach for GPRS services 
as specified in subclause 4.7.3.1.3 shall be followed. In addition, the following description for IMSI attach for non- 
GPRS services applies. 

The MS receiving the ATTACH ACCEPT message takes one of the following actions depending on the reject cause: 

# 2 (IMSI unknown in HLR) 

The MS shall stop timer T3310 if still running and shall reset the routing area updating attempt counter. The 
MS shall set the update status to U3 ROAMING NOT ALLOWED and shall delete any TMSI, LAI and 
ciphering key sequence number. The MS shall enter state GMM-REGISTERED. NORMAL-SERVICE. The 
new MM state is MM IDLE. The SIM/USIM shall be considered as invaUd for non-GPRS services until 
switching off or the SIM/USIM is removed. 

#16 (MSC temporarily not reachable) 

#17 (Network failure); or 

# 22 (Congestion) 

The MS shall change to state GMM-REGISTERED.ATTEMPTING-TO-UPDATE-MM. Timer T3310 shall 
be stopped if still running. The routing area updating attempt counter shall be incremented. 

If the routing area updating attempt counter is less than 5, and the stored RAI is equal to the RAJ of the 
current serving cell and the GMM update status is equal to GUI UPDATED: 

- the MS shall keep the GMM update status GUI UPDATED and changes state to GMM- 
REGISTERED. ATTEMPTING-TO-UPDATE-MM. The MS shall start timer T3311. When timer T3311 
expires the combined routing area update procedure indicating "combined RA/LA updating with IMSI 
attach" is triggered again. 

If the routing area updating attempt counter is greater than or equal to 5: 

- the MS shall start timer T3302 and shall change to state GMM-REGISTERED .ATTEMPTING-TO- 
UPDATE-MM; 

a GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific 
procedure; a GPRS MS operating in MS operation mode B may then proceed with appropriate MM 
specific procedures. The MM sublayer shall act as in network operation mode II or III (depending 
whether a PCCCH is present) as long as the combined GMM procedures are not successful and no new 
RA is entered. The new MM state is MM IDLE. 

Other reject cause values and the case that no GMM cause IE was received are considered as abnormal cases. The 
combined attach procedure shall be considered as failed for GPRS and non-GPRS services. The behaviour of the MS in 
those cases is specified in subclause 4.7.3.2.5. 

4.7.3.2.4 Combined GPRS attach not accepted by the network 

If the attach request can neither be accepted by the network for GPRS nor for non-GPRS services, an ATTACH 
REJECT message is transferred to the MS. The MS receiving the ATTACH REJECT message stops timer T3310, and 
for all causes except #12, #14, #15, #22 and #25 deletes the list of "equivalent PLMNs". 

If the attach request is rejected due to NAS level mobility management congestion control, the network shall set the 
MM cause value to #22 "congestion" and assign a back-off timer T3346. 
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The MS shall then take one of the following actions depending upon the reject cause: 

# 3 (Illegal MS); 

# 6 (Illegal ME), or 

# 8 (GPRS services and non-GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The new GMM state is GMM-DEREGISTERED. The new MM state is MM IDLE. 

The MS shall set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI and 
ciphering key sequence number. The SIM/USIM shall be considered as invalid for GPRS and non-GPRS 
services until switching off or the SIM/USIM is removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
combined attach procedure is rejected with the EMM cause with the same value. 

# 7 (GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The SIM/USIM shall be considered as invaUd for GPRS services until switching off or the SIM/USIM 
is removed. The new GMM state is GMM-DEREGISTERED; the MM state is MM IDLE. 

A GPRS MS operating in MS operation mode A or B which is already IMSI attached for CS services in the 
network is still IMSI attached for CS services in the network. 

A GPRS MS operating in MS operation mode A or B shall proceed with the appropriate MM specific procedure 
according to the MM service state. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
combined attach procedure is rejected with the EMM cause with the same value. 

# 1 1 (PLMN not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and changes to state GMM-DEREGISTERED. 

The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt 
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE. 

The MS shall store the PLMN identity in the "forbidden PLMN list". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall perform a PLMN selection according to 3GPP TS 23.122 [14]. 

An MS in GAN mode shall request a PLMN hst in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN 
selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the combined attach procedure is rejected with the EMM cause with the same value. 

# 12 (Location area not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature GPRS ciphering key sequence number, shall set the 
GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE. 
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The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt 
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE. 

The MS shall store the LAI in the list of "forbidden location areas for regional provision of service". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE I : The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the combined attach procedure is rejected with the EMM cause with the same value. 

#13 (Roaming not allowed in this location area); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE or optionally to GMM-DEREGISTERED.PLMN-SEARCH. 

The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt 
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE. 

The mobile station shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall perform a PLMN selection according to 3GPP TS 23.122 [14]. 

An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN 
selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the combined attach procedure is rejected with the EMM cause with the same value. 

# 14 (GPRS services not allowed in this PLMN); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and shall change to state GMM- 
DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. 

As an implementation option, a GPRS MS operating in operation mode A or B may perform a PLMN selection 
according to 3GPP TS 23.122 [14]. 

If an MS in GAN mode performs a PLMN selection, it shall request a PLMN hst in GAN (see 

3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23.122 [14]. 

The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause 
is: 

On the "User Controlled PLMN Selector with Access Technology " or. 

On the "Operator Controlled PLMN Selector with Access Technology " list or, 

A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above. 

If the MS does not perform a PLMN selection then a GPRS MS operating in MS operation mode A or B which 
is not yet IMSI attached for CS services in the network shall then perform an IMSI attach for non-GPRS services 
according to the conditions for the MM IMSI attach procedure (see subclause 4.4.3). 
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A GPRS MS operating in MS operation mode A or B which is already IMSI attached for CS services in the 
network is still IMSI attached for CS services in the network. 

A GPRS MS operating in MS operation mode A or B shall proceed with the appropriate MM specific procedure 
according to the MM service state. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the combined attach procedure is rejected with the EMM cause with the same value. 

# 15 (No Suitable Cells In Location Area); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED .LIMITED- 
SERVICE. 

The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt 
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN according to 
3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121]. 

NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the combined attach procedure is rejected with the EMM cause with the same value. 

# 22 (Congestion); 

If the T3346 value IE is present in the ATTACH REJECT message and the value indicates that this timer is 
neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be considered as an 
abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.3.1.5. 

The MS shall abort the attach procedure, reset the attach attempt counter, set the GPRS update status to GU2 
NOT UPDATED and enter state GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH. 

The MS shall stop timer T3346 if it is running. 

If the ATTACH REJECT message is integrity protected, the MS shall start timer T3346 with the value provided 
in the T3346 value IE. 

If the ATTACH REJECT message is not integrity protected, the MS shall start timer T3346 with a random value 
from the default range specified in table 1 1.3a. 

The MS stays in the current serving cell and applies the normal cell reselection process. The attach procedure is 
started, if still necessary, when timer T3346 expires or is stopped. 

A GPRS MS operating in MS operation mode A or B which is already IMSI attached for CS services in the 
network is still IMSI attached for CS services in the network. 

# 25 (Not authorized for this CSG) 

Cause #25 is only applicable in UTRAN lu mode and when received from a CSG cell. Other cases are 
considered as abnormal cases and the specification of the mobile station behaviour is given in 
subclause 4.7.3.2.5. 

If the ATTACH REJECT message with cause #25 was received without integrity protection, then the MS shall 
discard the message. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 147 ETSI TS 124 008 VI 0.1 0.0 (2013-04) 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall reset the GPRS attach attempt counter. The state is changed to GMM- 
DEREGISTERED.LIMITED-SERVICE. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST 
message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry corresponding to 
this CSG ID and associated PLMN identity from the Allowed CSG list. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST 
message are contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14] 
subclause 3.1 A. 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when the combined attach procedure is rejected with the EMM cause with the same value. 

Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is specified in 
subclause 4.7.3.2.5. 

4.7.3.2.5 Abnormal cases in the MS 

The MS shall proceed as follows: 

If the combined attach was successful for GPRS services only and the ATTACH ACCEPT message contained a 
cause value not treated in subclause 4.7.3.2.3.2 or the GMM Cause IE is not included in the message, the MS 
shall follow the procedure specified in subclause 4.7.3.1.5 step d), with the following modification; 

Otherwise, the abnormal cases specified in subclause 4.7.3.1.5 apply with the following modification. 

If the GPRS attach attempt counter is incremented according to subclause 4.7.3.1.5 the next actions depend on the 
Location Area Identities (stored on SIM/USIM and the one of the current serving cell) and the value of the attach 
attempt counter: 

if the update status is Ul UPDATED, and the stored LAI is equal to the one of the current serving cell and the 
attach attempt counter is smaller than 5, then the mobile station shall keep the update status to Ul UPDATED, 
the new MM state is MM IDLE substate NORMAL SERVICE; 

if the attach attempt counter is smaller than 5 and, additionally, the update status is different from Ul 
UPDATED or the stored LAI is different from the one of the current serving cell, then the mobile station shall 
delete any LAI, TMSI, ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs 
and set the update status to U2 NOT UPDATED. The MM state remains MM LOCATION UPDATING 
PENDING; or 

if the attach attempt counter is greater or equal to 5, then the mobile station shall delete any LAI, TMSI, 
ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs and set the update status 
to U2 NOT UPDATED. 

A GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific procedure; a 
GPRS MS operating in MS operation mode B may then proceed with appropriate MM specific procedures. 
The MM sublayer shall act as in network operation mode II or III (depending whether a PCCCH is present) as 
long as the combined GMM procedures are not successful and no new RA is entered. The new MM state is MM 
IDLE substate ATTEMPTING TO UPDATE or optionally MM IDLE substate PLMN SEARCH in order to 
perform a PLMN selection according to 3GPP TS 23.122 [14]. 

4.7.3.2.6 Abnormal cases on the network side 

The abnormal cases specified in subclause 4.7.3.1.6 apply with the exceptions for cases a and c in which in addition to 
the P-TMSI and P-TMSI signature the old TMSI shall be considered occupied until the new TMSI is used by the MS in 
a subsequent message. 
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4.7.4 GPRS detach procedure 

4.7.4.0 General 

The GPRS detach procedure is used: 

to detach the IMSI for GPRS services only. Independent of the network operation mode, this procedure is used 
by all kind of GPRS MSs; 

as a combined GPRS detach procedure used by GPRS MSs operating in MS operation mode A or B to detach the 
IMSI for GPRS and non-GPRS services or for non-GPRS services only, if the network operates in network 
operation mode I and no circuit-switched transaction is ongoing; 

in the case of a network failure condition to indicate to the MS that a re-attach with successive activation of 
previously active PDP contexts shall be performed. In this case, the MS may also perform the procedures needed 
in order to activate any previously active multicast service(s); or 

to detach the IMSI or IMEI for emergency bearer services. 

After completion of a GPRS detach procedure or combined GPRS detach procedure for GPRS and non-GPRS services 
the GMM context is released. 

An eCall only mobile station shall not perform any kind of GPRS detach procedure. 

The GPRS detach procedure shall be invoked by the MS if the MS is switched off, the SIM/USIM card is removed from 
the MS or if the GPRS or non-GPRS capability of the MS is disabled. The procedure may be invoked by the network to 
detach the IMSI for GPRS services. The GPRS detach procedure causes the MS to be marked as inactive in the network 
for GPRS services, non-GPRS services or both services. 

If a detach is requested by the HLR for an MS that has a PDP context for emergency services, the SGSN shall not send 
a DETACH REQUEST message to the MS, and shall follow the procedure described in subclause 6.1.3.4.2 for an MS 
that has PDP contexts for emergency bearer services. 

After the completion of application for which the emergency services were invoked, in order to regain normal services, 
an MS attached for emergency bearer services may perform a detach procedure, followed by a subsequent re-attach, if 
the MS moves to a new cell that provides normal service. 

In A/Gb mode, if the GPRS detach procedure is performed, the PDP contexts and the MBMS contexts, if any, are 
deactivated locally without peer to peer signalling between the SM and LLC entities in the MS and the network. 

In lu mode, if the GPRS detach procedure is performed, the PDP contexts and the MBMS contexts, if any, are 
deactivated locally without peer to peer signalling between the SM entities in the MS and the network. 

If the MS supports S 1 mode, the MS shall store the TIN in the non-volatile memory in the ME, as described in 
3GPP TS 24.301 [120], annex C, for a subsequent attach procedure. 

The MS is allowed to initiate the GPRS detach procedure even if the timer T3346 is running. 

The network proceeds with the GPRS detach procedure even if NAS level mobility management congestion control is 

active. 

4.7.4.1 MS initiated GPRS detach procedure 
4.7.4.1 .1 MS initiated GPRS detach procedure initiation 

The GPRS detach procedure is initiated by the MS by sending a DETACH REQUEST message. The detach type 
information element may indicate "GPRS detach with switching off, "GPRS detach without switching off", "IMSI 
detach", "GPRS/IMSI detach with switching off or "GPRS/IMSI detach without switching off. 

If the MS has a valid P-TMSI, the MS shall include the P-TMSI in the DETACH REQUEST message. The MS shall 
also include a valid P-TMSI signature, if available. 

If the MS is not switched off and the MS is in the state GMM_REGISTERED, timer T3321 shall be started after the 
DETACH REQUEST message has been sent. If the detach type information element value indicates "IMSI Detach" the 
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MS shall enter GMM-REGISTERED.IMSI-DETACH_INITIATED, otherwise the MS shall enter the state GMM- 
DEREGISTERED-INITIATED. If the detach type information element value indicates "IMSI Detach" or "GPRS/IMSI 
Detach", state MM IMSI DETACH PENDING is entered. If the MS is to be switched off, the MS shall try for a period 
of 5 seconds to send the DETACH REQUEST message. If the MS is able to send the DETACH REQUEST message 
during this time the MS may be switched off. 

If the detach type information element value indicates "GPRS detach without switching off " and the MS is attached for 
GPRS and non-GPRS services and the network operates in network operation mode I, then if in the MS the timer T3212 
is not already running, the timer T3212 shall be set to its initial value and restarted after the DETACH REQUEST 
message has been sent. 

4.7.4.1 .2 MS initiated GPRS detach procedure completion for GPRS services only 

When the DETACH REQUEST message is received by the network, the network shall send a DETACH ACCEPT 
message to the MS, if the detach type IE value indicates that the detach request has not been sent due to switching off. If 
switching off was indicated, the procedure is completed when the network receives the DETACH REQUEST message. 
The network and the MS shall deactivate the PDP contexts, the MBMS contexts and deactivate the logical link(s), if 
any. 

The MS is marked as inactive in the network for GPRS services; state GMM-DEREGISTERED is entered in the MS 
and the network. 

In lu mode, if the detach has been sent due to switching off, then the network shall release the resources in the lower 
layers for this MS (see 3GPP TS 25.331 [23c]). 

NOTE: When the DETACH REQUEST message is received by the network, and if the detach type IE value 

indicates that the detach is not due to power off, the authentication and ciphering procedure as well as the 
identification procedure may be performed. 

4.7.4.1 .3 MS initiated combined GPRS detach procedure completion 

When the DETACH REQUEST message is received by the network, a DETACH ACCEPT message shall be sent to the 
MS, if the detach type IE value indicates that the detach request has not been sent due to switching off. Depending on 
the value of the detach type IE the following applies: 

GPRS/IMSI detach: 

The MS is marked as inactive in the network for GPRS and for non-GPRS services. The network and the MS shall 
deactivate the PDP contexts, the MBMS contexts and deactivate the logical link(s), if any. The States GMM- 
DEREGISTERED and MM NULL are entered in both the MS and the network. 

In lu mode, if the detach has been sent due to switching off, then the network shall release the resources in the lower 
layers for this MS (see 3GPP TS 25.331 [23c]). 

IMSI detach: 

The MS is marked as inactive in the network for non-GPRS services. State MM NULL is entered in the MS and the 

network. 

4.7.4.1 .4 Abnormal cases in the MS 

The following abnormal cases can be identified: 

a) T3321 time-out 

On the first expiry of the timer, the MS shall retransmit the DETACH REQUEST message and shall reset and 
restart timer T332L This retransmission is repeated four times, i.e. on the fifth expiry of timer T3321, the GPRS 
detach procedure shall be aborted, the MS shall change to state: 

- MM-NULL if "IMSI detach" was requested; 

- GMM-REGISTERED.NORMAL-SERVICE if "IMSI Detach" was requested; 

- GMM-DEREGISTERED if "GPRS detach" was requested; 

- GMM-DEREGISTERED and MM-NULL if "GPRS/IMSI" detach was requested. 
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b) Lower layer failure before reception of DETACH ACCEPT message 

The detach procedure is aborted and the MS shall change to one of the following states, except in the following 
implementation option cases b.l, b.2 and b3: 

- MM-NULL if "IMSI detach" was requested; 

- GMM-REGISTERED.NORMAL-SERVICE if "IMSI Detach" was requested; 

- GMM-DEREGISTERED if "GPRS detach" was requested; 

- GMM-DEREGISTERED and MM-NULL if "IMSI/GPRS" detach was requested. 

b.l) Release of PS signalling connection before the completion of the GPRS detach procedure 

The release of the PS signalling connection before completion of the GPRS detach procedure shall result in the 
GPRS detach procedure being initiated again, if the following conditions apply: 

i) The original GPRS detach procedure was initiated over an existing PS signalling connection; and 

ii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to 
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the 
DETACH REQUEST message was transmitted. 

b.2) RR release in lu mode (i.e. RRC connection release) with cause different than "Directed signalling 
connection re-establishment", for example, "Normal", or"User inactivity" (see 3GPP TS 25.331 [23c] and 
3GPPTS 44.118 [111]) 

The GPRS detach procedure shall be initiated again, if the following conditions apply: 

i) The original GPRS detach procedure was initiated over an exisiting RRC connection; and 

ii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to 
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the 
DETACH REQUEST message was transmitted. 

NOTE: The RRC connection release cause different than "Directed signalling connection re-establishment" that 
triggers the re-initiation of the GPRS detach procedure is implementation specific. 

b.3) RR release in lu mode (i.e. RRC connection release) with cause "Directed signalling connection re- 
establishment" (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) 

The routing area updating procedure shall be initiated followed by completion of the GPRS detach procedure if 
the following conditions apply: 

i) The original GPRS detach procedure was not due to SIM removal; and 

ii) The original GPRS detach procedure was not due to a rerun of the procedure due to "Directed signalling 
connection reestablishment". 

c) Detach procedure collision 

If the MS receives a DETACH REQUEST message before the MS initiated GPRS detach procedure has been 
completed, the MS shall treat the message as specified in subclause 4.7.4.2.2 and send a DETACH ACCEPT 
message to the network. 

d) Detach and GMM common procedure collision 

GPRS detach containing cause "power off: 

If the MS receives a message used in a GMM common procedure before the GPRS detach procedure has 
been completed, this message shall be ignored and the GPRS detach procedure shall continue. 

GPRS detach containing other causes than "power off": 
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- If the MS receives a P-TMSI REALLOCATION COMMAND, a GMM STATUS, or a GMM 
INFORMATION message before the GPRS detach procedure has been completed, this message shall be 
ignored and the GPRS detach procedure shall continue. 

- If the MS receives an AUTHENTICATION AND CIPHERING REQUEST or IDENTITY REQUEST 
message, before the GPRS detach procedure has been completed, the MS shall respond to it as described in 

subclauses 4.7.7 and 4.7.8 respectively. 

e) Change of cell within the same RA (A/Gb mode only) 

If a cell change occurs within the same RA before a DETACH ACCEPT message has been received, then the 
cell update procedure shall be performed before completion of the detach procedure. 

f) Change of cell into a new routing area 

If a cell change into a new routing area occurs before a DETACH ACCEPT message has been received, the 
GPRS detach procedure shall be aborted and re-initiated after successfully performing a routing area updating 
procedure. If the detach procedure is performed due to the removal of the SIM/USIM the MS shall abort the 
detach procedure and enter the state GMM-DEREGISTERED. 

g) Access barred because of access class control 

The signalling procedure for GPRS detach shall not be started. The MS starts the signalling procedure as soon as 
possible and if still necessary, i.e. when the barred state is removed or because of a cell change, or performs a 
local detach immediately or after an implementation dependent time. 
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Figure 4.7.4/1 3GPP TS 24.008: MS initiated GPRS detach procedure 

4.7.4.1 .5 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) CSG ID of the CSG cell is not in the Allowed CSG list of the MS which sends the detach request 

If the MS initiates a detach procedure in a CSG cell the CSG ID of which is not valid for the MS and the detach 
procedure is not due to "switch off", the network shall proceed as follows: 

if the detach type is "IMSI detach" and the MS has a PDN connection for emergency bearer services active, 
the SGSN shall send a DETACH ACCEPT message and deactivate all non-emergency PDP contexts, if any, 
by initiating a PDP context deactivation procedure; 

otherwise, the network shall initiate the detach procedure. The network shall send a DETACH REQUEST 
message including the GMM cause value #25 "not authorized for this CSG", to indicate to the MS to remove 
the CSG ID and associated PLMN identity of the cell, where the MS has sent the DETACH REQUEST 
message, from the Allowed CSG list. 
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4.7.4.2 Network initiated GPRS detach procedure 

4.7.4.2.1 Network initiated GPRS detach procedure initiation 

The network initiates the GPRS detach procedure by sending a DETACH REQUEST message to the MS. The 
DETACH REQUEST message shall include a detach type IE. In addition, the network may include a cause IE to 
specify the reason for the detach request. The network shall start timer T3322. If the detach type IE indicates "re-attach 
required", or "re-attach not required" and the cause code is not #2 "IMSI unknown in HLR", the network shall 
deactivate the PDP contexts, the MBMS contexts and deactivate the logical link(s), if any, and shall change to state 
GMM-DEREGISTERED-INITIATED. 

4.7.4.2.2 Network initiated GPRS detach procedure completion by the MS 

When receiving the DETACH REQUEST message and the detach type indicates "re-attach required", the MS shall 
deactivate the PDP context(s), the MBMS context(s) and deactivate the logical link(s), if any. The MS shall stop the 
timer T3346, if it is running. The MS shall also stop timer(s) T3396, if it is running. The MS shall send a DETACH 
ACCEPT message to the network and shall enter the state GMM-DEREGISTERED. The MS shall, after the completion 
of the GPRS detach procedure, initiate a GPRS attach procedure. The MS should also activate PDP context(s) that were 
originally activated by the MS to replace any previously MS activated PDP context(s). The MS should also perform the 
procedures needed in order to activate any previously active multicast service(s). 

NOTE 1: When the detach type indicates "re-attach required", user interaction is necessary in some cases when the 
MS cannot re-activate the PDP/MBMS context(s) automatically. 

A GPRS MS operating in MS operation mode A or B in network operation mode I, which receives an DETACH 
REQUEST message with detach type indicating "re-attach required" or "re-attach not required" and no cause code, is 
only detached for GPRS services in the network. 

When receiving the DETACH REQUEST message and the detach type IE indicates "IMSI detach", the MS shall not 
deactivate the PDP/MBMS contexts. The MS shall set the MM update status to U2 NOT UPDATED. An MS in 
operation mode A or B in network operation mode I may send a DETACH ACCEPT message to the network, and shall 
re-attach to non-GPRS service by performing the combined routing area updating procedure according to 
subclause 4.7.5.2, sending a ROUTING AREA UPDATE REQUEST message with Update type IE indicating 
"combined RA/LA updating with IMSI attach". An MS in operation mode A that is in an ongoing circuit-switched 
transaction shall initiate the combined routing area updating after the circuit-switched transaction has been released. An 
MS in operation mode C, or in MS operation mode A or B in network operation mode II or III, shall send a DETACH 
ACCEPT message to the network. 

If the detach type IE indicates "IMSI detach", or "re-attach required" then the MS shall ignore the cause code if 
received. 

If the detach type information element value indicates "re-attach required" or "re-attach not required" and the MS is 
attached for GPRS and non-GPRS services and the network operates in network operation mode I, then if in the MS the 
timer T3212 is not already running, the timer T3212 shall be set to its initial value and restarted. 

When receiving the DETACH REQUEST message and the detach type IE indicates "re-attach not required" and the 
cause code is not #2 "IMSI unknown in HLR", the MS shall deactivate the PDP contexts, the MBMS contexts and 
deactivate the logical link(s), if any. The MS shall then send a DETACH ACCEPT message to the network and shall 
change state to GMM-DEREGISTERED. 

If the detach type IE indicates "re-attach not required", then, depending on the received cause code, the MS shall act as 
follows: 

# 2 (IMSI unknown in HLR); 

The MS shall set the update status to U3 ROAMING NOT ALLOWED and shall delete any TMSI, LAI and 
ciphering key sequence number. The new MM state is MM IDLE. The SIM/USIM shall be considered as invalid 
for non-GPRS services until switching off or the SIM/USIM is removed. 

A GPRS MS operating in MS operation mode A or B in network operation mode I, is still IMSI attached for 
GPRS services in the network. 

# 3 (Illegal MS); 
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# 6 (Illegal ME); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The new GMM state is GMM-DEREGISTERED. The SIM/USIM shall be considered as invalid for 
GPRS services until switching off or the SIM/USIM is removed. 

A GPRS MS operating in MS operation mode A or B shall in addition set the update status to U3 ROAMING 
NOT ALLOWED, shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in 
MS operation mode A and an RR connection exists, the MS shall abort the RR connection, unless an emergency 
call is ongoing. The SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or 
the SIM/USIM is removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Ust and KSI as specified in 3GPP TS 24.301 [120] for the case when a 
DETACH REQUEST is received with the EMM cause with the same value and with detach type set to "re-attach 
not required". 

NOTE 2: The possibility to configure an MS so that the radio transceiver for a specific radio access technology is 
not active, although it is implemented in the MS, is out of scope of the present specification. 

# 7 (GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM 
is removed. The new state is GMM-DEREGISTERED. 

A GPRS MS operating in MS operation mode A or B in network operation mode I shall set the timer T3212 to 
its initial value and restart it, if it is not already running. 

A GPRS MS operating in MS operation mode A or B in network operation mode I, is still IMSI attached for CS 
services in the network. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when a 
DETACH REQUEST is received with the EMM cause with the same value and with detach type set to "re-attach 
not required". 

# 8 (GPRS services and non-GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The new GMM state is GMM-DEREGISTERED. 

The MS shall set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI and 
ciphering key sequence number. If the MS is operating in MS operation mode A and an RR connection exists, 
the MS shall abort the RR connection, unless an emergency call is ongoing. The SIM/USIM shall be considered 
as invalid for GPRS and non-GPRS services until switching off or the SIM/USIM is removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when a 
DETACH REQUEST is received with the EMM cause with the same value and with detach type set to "re-attach 
not required". 

# 1 1 (PLMN not allowed); 

The MS shall delete any RAI or LAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall reset the GPRS attach attempt counter. The new GMM state is GMM- 
DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMN list". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 154 ETSI TS 124 008 VI 0.1 0.0 (2013-04) 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- A GPRS MS operating in MS operation mode A or B shall set the update status to U3 ROAMING NOT 
ALLOWED and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM 
IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [14]. 

An MS in GAN mode shall request a PLMN Hst in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach 
type set to "re-attach not required". 

# 12 (Location area not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature GPRS ciphering key sequence number, shall set the 
GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for regional provision of service". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach 
type set to "re-attach not required". 

#13 (Roaming not allowed in this location area); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE or optionally to GMM-DEREGISTERED.PLMN-SEARCH. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [14]. 
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An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAX list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach 
type set to "re-attach not required". 

# 14 (GPRS services not allowed in this PLMN); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and shall change to state GMM- 
DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. 

A GPRS MS operating in MS operation mode A or B in network operation mode I shall set the timer T3212 to 
its initial value and restart it, if it is not already running. 

A GPRS MS operating in MS operation mode A or B, is still IMSI attached for CS services in the network. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach 
type set to "re-attach not required". 

# 15 (No Suitable Cells In Location Area); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and 
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED- 
SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN 
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121]. 

NOTE 4: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach 
type set to "re-attach not required" . 

# 25 (Not authorized for this CSG) 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and store it according to 
subclause 4.1.3.2) and shall reset the GPRS attach attempt counter. The state is changed to GMM- 
DEREGISTERED.LIMITED-SERVICE. 

If the cell where the MS has received the DETACH REQUEST message is a CSG cell and the CSG ID and 
associated PLMN identity of the cell are contained in the Allowed CSG list stored in the MS, the MS shall 
remove the CSG ID and associated PLMN identity from the Allowed CSG list. 
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If the cell where the MS has received the DETACH REQUEST message is a CSG cell and the CSG ID and 
associated PLMN identity of the cell are contained in the Operator CSG list, the MS shall proceed as specified in 
3GPP TS 23.122 [14] subclause 3.1A. 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120] 
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach 
type set to "re-attach not required". 

NOTE 4: CSG is appHcable only for UMTS. 

Other cause values shall not impact the update status. Further actions of the MS are implementation dependent. 

4.7.4.2.3 Network initiated GPRS detach procedure completion by the network 

The network shall, upon receipt of the DETACH ACCEPT message, stop timer T3322. If the detach type IE included in 
the DETACH REQUEST message indicates "re-attach required", or "re-attach not required" and the cause code is not 
#2 "IMSI unknown in HLR", the network shall change state to GMM-DEREGISTERED. If the detach type IE included 
in the DETACH REQUEST message indicates "IMSI detach", the network shall not change the current GMM state. 

4.7.4.2.4 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) T3322 time-out 

On the first expiry of the timer, the network shall retransmit the DETACH REQUEST message and shall start 
timer T3322. This retransmission is repeated four times, i.e. on the fifth expiry of timer T3322, the GPRS detach 
procedure shall be aborted and the network changes to state GMM-DEREGISTERED. 

b) Low layer failure 

The GPRS detach procedure is aborted and the network changes to state GMM-DEREGISTERED. 

c) GPRS detach procedure collision 

If the network receives a DETACH REQUEST message with "switching off indicated, before the network 
initiated GPRS detach procedure has been completed, both procedures shall be considered completed. 

If the network receives a DETACH REQUEST message without "switching off indicated, before the network 
initiated GPRS detach procedure has been completed, the network shall send a DETACH ACCEPT message to 
the MS. 

d) GPRS detach and GPRS attach procedure collision 

If the network receives an ATTACH REQUEST message before the network initiated GPRS detach procedure 
with type of detach 're-attach not required' has been completed, the network shall ignore the ATTACH 
REQUEST message. If the detach type IE value, sent in the DETACH REQUEST message, indicates "re-attach 
required" the detach procedure is aborted and the GPRS attach procedure shall be progressed after the PDP 
contexts and MBMS contexts, if any, have been deleted. If the detach type IE value, sent in the DETACH 
REQUEST message, indicates "IMSI detach" the detach procedure is aborted and the GPRS attach procedure 
shall be progressed. 

e) GPRS detach and routing area updating procedure collision 

GPRS detach containing detach type "re-attach required" or "re-attach not required": 

If the network receives a ROUTING AREA UPDATE REQUEST message before the network initiated 
GPRS detach procedure has been completed, the detach procedure shall be progressed, i.e. the ROUTING 
AREA UPDATE REQUEST message shall be ignored. If the DETACH REQUEST message contains detach 
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type "re-attach not required" and GMM cause #2 "IMSI unknown in HLR", the network will follow the 
procedure as described below for the detach type "IMSI detach". 

GPRS detach containing detach type "IMSI detach": 

If the network receives a ROUTING AREA UPDATE REQUEST message before the network initiated 
GPRS detach procedure has been completed, the network shall abort the detach procedure, shall stop T3322 
and shall progress the routing area update procedure. 

f) GPRS detach and service request procedure collision 

GPRS detach containing detach type "re-attach required" or "re-attach not required": 

If the network receives a SERVICE REQUEST message before the network initiated GPRS detach procedure 
has been completed, the network shall progress the detach procedure. If the GPRS Detach Request message 
contains detach type "re-attach not required" and GMM cause #2 "IMSI unknown in HLR", the network will 
follow the procedure as described below for the detach type "IMSI detach". 

GPRS detach containing detach type "IMSI detach": 

If the network receives a SERVICE REQUEST message before the network initiated GPRS detach procedure 
has been completed, the network shall progress both procedures. 



MS 


DETACH REQUEST 


Network 




DETACH ACCEPT 


Stop T3322 





Figure 4.7.4/2 3GPP TS 24.008: Network initiated GPRS detach procedure 

4.7.5 Routing area updating procedure 

This procedure is used for: 

normal routing area updating to update the registration of the actual routing area of an MS in the network. This 
procedure is used by GPRS MSs in MS operation mode C and by GPRS MSs in MS operation modes A or B that 
are IMSI attached for GPRS and non-GPRS services if the network operates in network operation mode II or III; 

combined routing area updating to update the registration of the actual routing and location area of an MS in the 
network. This procedure is used by GPRS MSs in MS operation modes A or B that are IMSI attached for GPRS 
and non-GPRS services provided that the network operates in network operation mode I; 

periodic routing area updating. This procedure is used by GPRS MSs in MS operation mode C and by GPRS 
MSs in MS operation modes A or B that are IMSI attached for GPRS or for GPRS and non-GPRS services 
independent of the network operation mode; 

IMSI attach for non-GPRS services when the MS is IMSI attached for GPRS services. This procedure is used by 
GPRS MSs in MS operation modes A or B, if the network operates in network operation mode I; 

in A/Gb mode, resuming GPRS services when the RR sublayer indicated a resumption failure after dedicated 
mode was left, see 3GPP TS 44.018 [84]; 

in A/Gb mode, updating the network with the new MS Radio Access Capability IE when the content of the IE 
has changed; 

updating the network with the new DRX parameter IE when the content of the IE has changed; 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 10 1 58 ETSI TS 1 24 008 VI 0.1 0.0 (201 3-04) 

NOTE 1: Such changes can be used e.g. when the MS activates a PDP context with service requirements that 
cannot be met with the current DRX parameter. As PDP context(s) are activated and deactivated, the 
GMM context will be updated with an appropriate DRX parameter; 

re-negotiation of the READY timer value; 

lu mode to A/Gb mode and for A/Gb mode to lu mode intersystem change, see subclause 4.7.1.7; 

in lu mode, re-synchronizing the PMM mode of MS and network after RRC connection release with cause 
"Directed signalling connection re-establishment", see subclause 4.7.2.5; 

in lu mode and A/Gb mode after intersystem change from S 1 mode, and the GMM receives an indication of 
"RRC connection failure" from lower layers due to lower layer failure while in SI mode; 

SI mode to lu mode or SI mode to A/Gb mode intersystem change and ISR is not activated; 

SI mode to lu mode or SI mode to A/Gb mode intersystem change and ISR is activated, but the MS changes to a 
routeing area it has not previously registered with the network; 

indicating to the network that due to a manual CSG selection the MS has selected a CSG cell whose CSG 
identity and associated PLMN identity are not included in the MS's Allowed CSG list or in the MS's Operator 
CSG Hst; 

indicating to the network that the mobile station classmark 2, mobile station classmark 3 or the supported codecs 
have changed for a MS supporting SRVCC; or 

- indicating to the network that the MS's availability for voice calls in the IMS (see 3GPP TS 24.301 [120], 
subclause 3.1) has changed to "available". 

While an MS has a PDN connection for emergency bearer services, the MS shall not perform manual CSG selection. 

The routing area updating procedure shall also be used by a MS which is attached for GPRS services if a new PLMN is 
entered (see 3GPP TS 23.122 [14]), unless the MS is configured for "AttachWithlMSI" as specified in 
3GPP TS 24.368 [135] or 3GPP TS 31.102 [1 12] and the new PLMN is neither the registered PLMN nor in the hst of 
equivalent PLMNs. 

An eCall only mobile station shall not perform a normal or combined routing area updating procedure. 

Subclause 4.7.5.1 describes the routing area updating procedures for updating the routing area only. The combined 
routing area updating procedure used to update both the routing and location area is described in subclause 4.7.5.2. 

The routing area updating procedure is always initiated by the MS. It is only invoked in state GMM-REGISTERED. 

To limit the number of subsequently rejected routing area update attempts, a routing area updating attempt counter is 
introduced. The routing area updating attempt counter shall be incremented as specified in subclause 4.7.5.1.5. 
Depending on the value of the routing area updating attempt counter, specific actions shall be performed. The routing 
area updating attempt counter shall be reset when: 

a GPRS attach procedure is successfully completed; 

a routing area updating procedure is successfully completed; or 

a combined routing area updating procedure is completed for GPRS services only with cause #2; 

a routing area updating procedure is rejected with cause #11, #12, #13, #14, #15 or #25; 

and additionally when the MS is in substate ATTEMPTING-TO-UPDATE: 

a new routing area is entered; 

expiry of timer T3302; 

at request from registration function; or 

- timer T3346 is started. 
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The mobile equipment shall contain a list of "forbidden location areas for roaming", as well as a list of "forbidden 
location areas for regional provision of service". The handling of these lists is described in subclause 4.4.1. 

The Mobile Equipment shall contain a list of "equivalent PLMNs". The handling of this list is described in 
subclause 4.4.1. 

In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The MS 
shall construct the Routing Area Identification of the cell from this chosen PLMN identity, and the LAC and the RAC 
received on the BCCH. If the constructed RAI is different from the stored RAI, the MS shall initiate the routing area 
updating procedure. The chosen PLMN identity shall be indicated to the UTRAN in the RRC INITIAL DIRECT 
TRANSFER message (see 3GPP TS 25.331 [23c]). Whenever a ROUTING AREA UPDATING REJECT message with 
the cause "PLMN not allowed" is received by the MS, the chosen PLMN identity shall be stored in the "forbidden 
PLMN list". Whenever a ROUTING AREA UPDATING REJECT message is received by the MS with the cause 
"Roaming not allowed in this location area", "Location Area not allowed", or "No suitable cells in Location Area", the 
LAI that is part of the constructed RAI which triggered the routing area updating procedure shall be stored in the 
suitable list. 

In A/Gb mode, user data transmission in the MS shall be suspended during the routing area updating procedure, except 
if the routing area updating procedure is triggered by a PS handover procedure as described in 3GPP TS 43.129 [113]; 
user data reception shall be possible. User data transmission in the network may be suspended during the routing area 
updating procedure. 

In lu mode, user data transmission and reception in the MS shall not be suspended during the routing area updating 
procedure. User data transmission in the network shall not be suspended during the routing area updating procedure. 

In lu mode, when a ROUTING AREA UPDATE REQUEST is received by the SGSN over a new PS signalling 
connection while there is an ongoing PS signalling connection (network is already in mode PMM-CONNECTED) for 
this MS, the network shall progress the routing area update procedure as normal and release the previous PS signalling 
connection when the routing area update procedure has been accepted by the network. 

NOTE 2: The re-establishment of the radio bearers of active PDP contexts is done as described in subclause 
"Service Request procedure". 

The network informs the MS about the support of specific features, such as LCS-MOLR, MBMS, IMS voice over PS 
session, or emergency bearer services in lu mode in the "Network feature support" Information Element. The 
information is either explicitly given by sending the "Network feature support" IE or implicitly by not sending it. The 
handling in the network is described in subclause 9.4. 15. 1 1 . The MS may use the support indications for LCS-MOLR 
and MBMS to inform the user about the availability of the appropriate services. The MS shall not request any of these 
two services, if the service has not been indicated as available. The indication for MBMS is defined in subclause 
"MBMS feature support indication" in 3GPP TS 23.246 [106]. In an MS with IMS voice over PS capabiHty, the IMS 
voice over PS session indicator and the emergency bearer services indicator shall be provided to the upper layers. The 
upper layers take the IMS voice over PS session indicator into account as specified in 3GPP TS 23.221 [131], 
subclause 7.2a and subclause 7.2b, when selecting the access domain for voice sessions or calls in lu mode. When 
initiating an emergency call in lu mode, the upper layers also take the emergency bearer services indicator into account 
for the access domain selection. 

4.7.5.1 Normal and periodic routing area updating procedure 

Periodic routing area updating is used to periodically notify the availability of the MS to the network. The value of the 
update type IE in the ROUTING AREA UPDATE REQUEST message shall indicate "periodic updating". The 
procedure is controlled in the MS by timer T33I2. When timer T33I2 expires, the periodic routing area updating 
procedure is started. Start and reset of timer T3312 is described in subclause 4.7.2.2. 

The normal routing area updating procedure is initiated: 

- when the MS detects a change of the routing area in state GMM-REGISTERED; 

when the MS determines that GPRS resumption shall be performed; 

when the MS needs to update the network with the new MS Radio Access Capability IE; 

when the MS needs to update the network with the new DRX parameter IE; 
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in lu mode, to re-synchronize the PMM mode of MS and network after RRC connection release with cause 
"Directed signalling connection re-establishment", see subclause 4.7.2.5; 

in lu mode and A/Gb mode, after intersystem change from S 1 mode, and the GMM receives an indication of 
"RRC connection failure" from lower layers due to lower layer while in SI mode; 

in A/Gb mode, after intersystem change from SI mode if the TIN indicates "RAT-related TMSI", but the MS is 
required to perform routing area updating for IMS voice termination as specified in annex P. 4; 

- when the MS enters GMM-REGISTERED.NORMAL-SERVICE and the TIN indicates "GUTI" ; 

when the MS has selected a CSG cell whose CSG identity and associated PLMN identity are not included in the 
Allowed CSG list;or in the Operator CSG list; 

when the MS supports SRVCC and changes the mobile station classmark 2, mobile station classmark 3 or the 
supported codecs; 

when the MS changes the MS network capability information; 

when the UE's usage setting or the voice domain preference for E-UTRAN change in the MS; 

when the MS activates mobility management for IMS voice termination as specified in annex P. 2 and the TIN 
indicates "RAT-related TMSI"; or 

upon reception of a paging indication, using P-TMSI, if the timer T3346 is running and the MS is in state GMM- 
REGISTERED.ATTEMPTING-TO-UPDATE. 

The ROUTING AREA UPDATE REQUEST message shall always be the first data sent by the MS when a routing area 
border is crossed. The routing area identification is broadcast on the broadcast channel(s). 

A normal routing area updating shall abort any ongoing GMM procedure. Aborted GMM procedures may be repeated 
after the normal routing area updating procedure has been successfully performed. The value of the update type IE 
included in the message shall indicate "RA updating". 

If the normal routing area updating procedure is initiated due to the reception of the paging indication while T3346 is 
running, the "follow-on request pending" indication shall be set to 1 . 

4.7.5.1 .1 Normal and periodic routing area updating procedure initiation 

To initiate the normal routing area updating procedure, the MS sends the message ROUTING AREA UPDATE 
REQUEST to the network, starts timer T3330 and changes to state GMM-ROUTING-AREA-UPDATING- 
INITIATED. 

If the MS supports SI mode, the MS shall handle the P-TMSI IE as follows: 

- If the TIN indicates "GUTI" and the MS holds a valid GUTI, the MS shall map the GUTI into a P-TMSI, 
P-TMSI signature and RAI as specified in 3GPP TS 23.003 [4]. The MS shall include the mapped RAI in the 
Old routing area identification IE and the mapped P-TMSI signature in the P-TMSI signature IE. In addition, the 
MS shall include the P-TMSI type IE with P-TMSI type set to "mapped P-TMSI". When the routing area 
updating procedure is initiated in lu mode, the MS shall also include the mapped P-TMSI in the P-TMSI IE. 
Additionally, in lu mode and A/Gb mode, if the MS holds a valid P-TMSI and RAI, the MS shall indicate the P- 
TMSI in the Additional mobile identity IE and the RAI in the Additional old routing area identification IE. 

- If the TIN indicates "P-TMSI" or "RAT-related TMSI" and the MS holds a valid P-TMSI and RAI, the MS shall 
indicate the RAI in the Old routing area identification IE. In addition, the MS shall include the P-TMSI type IE 
with P-TMSI type set to "native P-TMSI". When the routing area updating procedure is initiated in lu mode, the 
MS shall also include the P-TMSI in the P-TMSI IE. 

If the MS does not support SI mode, the MS shall include the P-TMSI type IE with P-TMSI type set to "native P- 
TMSI". 

If the routing area updating procedure is not initiated by the MS due to an S 1 mode to lu mode or S 1 mode to A/Gb 
mode intersystem change, or if it is initiated due to such an intersystem change and the TIN indicates "RAT-related 
TMSI", the MS shall use the existing UMTS security context for the PS domain. The ROUTING AREA UPDATE 
REQUEST message shall contain the P-TMSI signature when received in a previous ATTACH ACCEPT or ROUTING 
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AREA UPDATE ACCEPT message. If the MS has a vahd UMTS security context, the MS shall indicate it in the GPRS 
ciphering key sequence number IE. 

If the routing area updating procedure is initiated by the MS due to an S 1 mode to lu mode or S 1 mode to A/Gb mode 
inter-system change in idle mode and the TIN indicates "GUTI", the MS shall derive a UMTS security context for the 
PS domain from the current EPS security context as described in the subclause 4.7.7.10. The ROUTING AREA 
UPDATE REQUEST message shall include a P-TMSI signature filled with a NAS token as specified in 
3GPP TS 33.401 [119]. Furthermore, the MS shall indicate the eKSI value, which is associated with the derived UMTS 
security keys, in the CKSN field of the GPRS GSM ciphering key sequence number IE in the ROUTING AREA 
UPDATE REQUEST message. 

NOTE: When the MS includes a P-TMSI signature filled with a NAS token, 8 bits of the NAS token will be filled 
with bits from the M-TMSI (see 3GPP TS 23.003 [4]). 

If the routing area updating procedure is initiated by the MS due to the S 1 mode to lu mode or S 1 mode to A/Gb mode 
inter-system change in connected mode, the MS shall derive a UMTS security context for the PS domain from the 
current EPS security context station as described in the subclause 4.7.7.10. Furthermore, the MS shall indicate the eKSI 
value, which is associated with the derived UMTS security keys, in the CKSN field of the GPRS GSM ciphering key 
sequence number IE in the ROUTING AREA UPDATE REQUEST message. 

In lu mode, if the MS wishes to prolong the established PS signalling connection after the normal routing area updating 
procedure (for example, the MS has any CM application request pending), it may set a follow-on request pending 
indicator on (see subclause 4.7.13). 

In order to indicate the new DRX parameter while in GERAN or UTRAN coverage, the MS shall send the ROUTING 
AREA UPDATE REQUEST message containing the DRX parameter in the DRX parameter IE to the network, with the 
exception of the case if the MS had indicated its MS specific DRX parameter (3GPP TS 24.301 [120]) to the network 
while in E-UTRAN coverage. In this case, when the MS enters GERAN or UTRAN coverage and initiates a routing 
area updating procedure, the MS shall not include the DRX parameter in the DRX parameter IE in the ROUTING 
AREA UPDATE REQUEST message. 

4.7.5.1 .2 GMM Common procedure initiation 

If the network receives a ROUTING AREA UPDATE REQUEST message containing the P-TMSI type IE, and the 
network does not follow the use of the most significant bit of the <LAC> to distinguish the node type as specified in 
3GPP TS 23.003 [10] subclause 2.8.2.2.2, the network shall use the P-TMSI type IE to determine whether the mobile 
identity included in the P-TMSI IE, if any, or the mobile identity used by the MS to derive a foreign TLLI (see 
subclause 4.7.1.4.1) is a native P-TMSI or a mapped P-TMSI. 

The network may initiate GMM common procedures, e.g. the GMM authentication and ciphering procedure. 

4.7.5.1 .3 Normal and periodic routing area updating procedure accepted by the network 

If the routing area updating request has been accepted by the network, a ROUTING AREA UPDATE ACCEPT 
message shall be sent to the MS. The network may assign a new P-TMSI and/or a new P-TMSI signature for the MS. If 
a new P-TMSI and/or P-TMSI signature have been assigned to the MS, it/they shall be included in the ROUTING 
AREA UPDATE ACCEPT message together with the routing area identification. In a shared network, if the MS is 
supporting network sharing, the network shall indicate the PLMN identity of the CN operator that has accepted the 
routing area updating request in the RAI contained in the ROUTING AREA UPDATE ACCEPT message; if the MS is 
not supporting network sharing, the network shall indicate the PLMN identity of the common PLMN (see 
3GPPTS 23.251 [109]). 

In a multi-operator core network (MOCN) with common GERAN, the network shall indicate in the RAJ the common 
PLMN identity (see 3GPP TS 23.251 [109]). 

If a new DRX parameter was included in the ROUTING AREA UPDATE REQUEST message, the network shall store 
the new DRX parameter and use it for the downlink transfer of signalling and user data. 

If the MS has indicated in the ROUTING AREA UPDATE REQUEST message that it supports PS inter-RAT handover 
from GERAN to UTRAN lu mode, the network may include in the ROUTING AREA UPDATE ACCEPT message a 
request to provide the Inter RAT information container. 
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If the MS has indicated in the ROUTING AREA UPDATE REQUEST message that it supports PS inter-RAT HO from 
GERAN to E-UTRAN, the network may include in the ROUTING AREA UPDATE ACCEPT message a request to 
provide the E-UTRAN inter RAT information container. 

If the MS has included the MS network capabiUty IE or the UE network capability IE or both in the ROUTING AREA 
UPDATE REQUEST message, the network shall store all octets received from the MS, up to the maximum length 
defined for the respective information element. In case the UE network capability IE indicated new information to the 
network, the MS shall set the TIN to "P-TMSI". 

NOTE 1: This information is forwarded to the new SGSN during inter-SGSN handover or to the new MME during 
intersystem handover to SI mode. 

In A/Gb mode the Cell Notification information element shall be included in the ROUTING AREA UPDATE ACCEPT 
message in order to indicate the ability of the network to support the Cell Notification. 

The network shall change to state GMM-COMMON -PROCEDURE-INITIATED and shall start the supervision timer 
T3350 as described in subclause 4.7.6. 

If the LAI or PLMN identity contained in the ROUTING AREA UPDATE ACCEPT message is a member of any of 
the "forbidden" lists and there is no PDN connection for emergency bearer services in the MS then any such entry shall 
be deleted. 

In lu mode, the network should prolong the PS signalling connection if the mobile station has indicated a follow-on 
request pending in ROUTING AREA UPDATE REQUEST. The network may also prolong the PS signalling 
connection without any indication from the mobile terminal. 

If the PDP context status information element is included in ROUTING AREA UPDATE REQUEST message, then the 
network shall deactivate all those PDP contexts locally (without peer to peer signalling between the MS and the 
network), which are not in SM state PDP-INACTIVE on network side but are indicated by the MS as being in state 
PDP-INACTIVE. 

If the MBMS context status information element is included in the ROUTING AREA UPDATE REQUEST message, 
then the network shall deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and 
network) which are not in SM state PDP-INACTIVE on the network side, but are indicated by the MS as being in state 
PDP-INACTIVE. If no MBMS context status information element is included, then the network shall deactivate all 
MBMS contexts locally which are not in SM state PDP-INACTIVE on the network side. 

If a ROUTING AREA UPDATE REQUEST message is received from a MS with a LIPA PDN connection, and if: 

a L-GW Transport Layer Address is provided by the lower layer together with the ROUTING AREA UPDATE 
REQUEST message, and the GGSN address associated with the PDP context of the LIPA PDN connection is 
different from the provided L-GW Transport Layer Address (see 3GPP TS 25.413 [19c]); or 

- no L-GW Transport Layer Address is provided together with the ROUTING AREA UPDATE REQUEST 

message by the lower layer, 

then the SGSN locally deactivates all PDP contexts associated with the LIPA PDN connection. If the ROUTING AREA 
UPDATE REQUEST request message is accepted, the SGSN informs the MS via the PDP context status IE in the 
ROUTING AREA UPDATE ACCEPT message that PDP contexts were locally deactivated. 

If due to regional subscription restrictions or access restrictions the MS is not allowed to access the routing area, but the 
MS has a PDN connection for emergency bearer services established, the network may accept the ROUTING AREA 
UPDATE REQUEST message and deactivate all non-emergency PDP contexts by initiating an PDP context 
deactivation procedure when the RAU is initiated in PMM-CONNECTED mode. When the RAU is initiated in PMM- 
IDLE mode, the network locally deactivates all non-emergency PDP contexts and informs the MS via the PDP context 
status IE in the ROUTING AREA UPDATE ACCEPT message. The network shall not deactivate the PDP contexts for 
emergency bearer services. The network shall consider the MS to be attached for emergency bearer services only. 

Upon receipt of a ROUTING AREA UPDATE ACCEPT message, the MS stores the received routing area 
identification, stops timer T3330, shall reset the routing area updating attempt counter and sets the GPRS update status 
to GUI UPDATED. If the message contains a P-TMSI, the MS shall use this P-TMSI as new temporary identity for 
GPRS services and shall store the new P-TMSI. If no P-TMSI was included by the network in the ROUTING AREA 
UPDATING ACCEPT message, the old P-TMSI shall be kept. Furthermore, the MS shall store the P-TMSI signature if 
received in the ROUTING AREA UPDATING ACCEPT message. If no P-TMSI signature was included in the 
message, the old P-TMSI signature, if available, shall be deleted. 
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If the ROUTING AREA UPDATE REQUEST message was used to update the network with a new DRX parameter IE, 
the MS shall start using the new DRX parameter upon receipt of the ROUTING AREA UPDATE ACCEPT message 
and shall set the TIN to "P-TMSI". 

If the PDP context status information element is included in ROUTING AREA UPDATE ACCEPT message, then the 
MS shall deactivate all those PDP contexts locally (without peer to peer signalling between the MS and network), which 
are not in SM state PDP-INACTIVE in the MS but are indicated by the network as being in state PDP-INACTIVE. If 
only the PDN connection for emergency bearer services remains established, the MS shall consider itself attached for 
emergency bearer services only. 

If the MBMS context status information element is included in the ROUTING AREA UPDATE ACCEPT message, 
then the MS shall deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and 
network) which are not in SM state PDP-INACTIVE in the MS, but are indicated by the network as being in state PDP- 
INACTIVE. If no MBMS context status information element is included, then the MS shall deactivate all those MBMS 
contexts locally which are not in SM state PDP-INACTIVE in the MS. 

If the ROUTING AREA UPDATE ACCEPT message contains T3312 extended value IE, then the MS shall use the 
T3312 extended value IE as periodic routing area update timer (T3312). If the ROUTING AREA UPDATE ACCEPT 
message does not contain T3312 extended value IE, then the MS shall use value in T3312 value IE as periodic routing 
area update timer (T3312). 

In A/Gb mode, if the ROUTING AREA UPDATE ACCEPT message contains the Cell Notification information 
element, then the MS shall start to use the LLC NULL frame to perform cell updates. 

If the MS has initiated the routing area updating procedure due to manual CSG selection and receives a ROUTING 
AREA UPDATE ACCEPT message, and the MS sent the ROUTING AREA UPDATE REQUEST message in a CSG 
cell, the MS shall check if the CSG ID and associated PLMN identity of the cell are contained in the Allowed CSG list. 
If not, the MS shall add that CSG ID and associated PLMN identity to the Allowed CSG list and the MS may add the 
HNB Name (if provided by lower layers) to the Allowed CSG list if the HNB Name is present in neither the Operator 
CSG list nor the Allowed CSG Ust. 

The network may also send a list of "equivalent PLMNs" in the ROUTING AREA UPDATE ACCEPT message. Each 
entry of the list contains a PLMN code (MCCh-MNC). The mobile station shall store the list, as provided by the 
network, and if there is no PDN connection for emergency bearers established, the mobile station shall remove from the 
list of "equivalent PLMNs" any PLMN code that is already in the "forbidden PLMN" list. If there is a PDN connection 
for emergency bearer services established, the MS shall remove from the list of "equivalent PLMNs" any PLMN code 
present in the "forbidden PLMN" list when the PDN connection for emergency bearer services is released. In addition 
the mobile station shall add to the stored list the PLMN code of the registered PLMN that sent the list. All PLMNs in 
the stored list shall be regarded as equivalent to each other for PLMN selection, cell selection/re-selection and 
handover. The stored list in the mobile station shall be replaced on each occurrence of the ROUTING AREA UPDATE 
ACCEPT message. If no list is contained in the message, then the stored list in the mobile station shall be deleted. An 
MS attached for emergency bearer services only shall delete the stored list when the MS enters the state GMM- 
DEREGISTERED. The list shall be stored in the mobile station while switched off so that it can be used for PLMN 
selection after switch on. 

A ROUTING AREA UPDATE COMPLETE message shall be returned to the network if the ROUTING AREA 
UPDATE ACCEPT message contained any of: 

- a P-TMSI; 

- Receive N-PDU Numbers (see 3GPP TS 44.065 [78] and 3GPP TS 25.322 [19b]); or 

a request for the provision of Inter RAT handover information or E-UTRAN inter RAT handover information or 
both. 

If Receive N-PDU Numbers were included, the Receive N-PDU Numbers values valid in the MS, shall be included in 
the ROUTING AREA UPDATE COMPLETE message. 

If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover 
information or both, the MS shall return a ROUTING AREA UPDATE COMPLETE message including the Inter RAT 
handover information IE or E-UTRAN inter RAT handover information IE or both to the network. 
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NOTE 2: In lu mode, after a routing area updating procedure, the mobile station can initiate Service Request 
procedure to request the resource reservation for the active PDP contexts if the resources have been 
released by the network or send upper layer message (e.g. ACTIVATE PDP CONTEXT REQUEST) to 
the network via the existing PS signalling connection. 

In lu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has 
indicated "follow-on request pending" in ROUTING AREA UPDATE REQUEST message) the network shall indicate 
the "follow-on proceed" in the ROUTING AREA UPDATE ACCEPT message. If the network wishes to release the PS 
signalling connection, the network shall indicate "no follow-on proceed" in the ROUTING AREA UPDATE ACCEPT 

message. 

After that in lu mode, the mobile station shall act according to the follow-on proceed flag included in the Update result 
information element in the ROUTING AREA UPDATE ACCEPT message (see subclause 4.7.13). 

The network may also send a list of local emergency numbers in the ROUTING AREA UPDATE ACCEPT, by 
including the Emergency Number List IE. The mobile equipment shall store the list, as provided by the network, except 
that any emergency number that is already stored in the SIM/USIM shall be removed from the list before it is stored by 
the mobile equipment. If there are no emergency numbers stored on the SIM/USIM, then before storing the received list 
the mobile equipment shall remove from it any emergency number stored permanently in the ME for use in this case 
(see 3GPP TS 22.101 [8]). The list stored in the mobile equipment shall be replaced on each receipt of a new 
Emergency Number List IE. 

The emergency number(s) received in the Emergency Number List IE are valid only in networks with the same MCC as 
in the cell on which this IE is received. If no list is contained in the ROUTING AREA UPDATE ACCEPT message, 
then the stored list in the mobile equipment shall be kept, except if the mobile equipment has successfully registered to 
a PLMN with an MCC different from that of the last registered PLMN. 

The mobile equipment shall use the stored list of emergency numbers received from the network in addition to the 
emergency numbers stored on the SIM/USIM or ME to detect that the number dialled is an emergency number. 

NOTE 3: The mobile equipment may use the emergency numbers list to assist the end user in determining whether 
the dialled number is intended for an emergency service or for another destination, e.g. a local directory 
service. The possible interactions with the end user are implementation specific. 

The list of emergency numbers shall be deleted at switch off and removal of the SIM/USIM. The mobile equipment 
shall be able to store up to ten local emergency numbers received from the network. 

In order to indicate to the MS that the GUTI and TAI list assigned to the MS remain registered with the network and are 
valid in the MS, the network shall indicate in the Update result IE in the ROUTING AREA UPDATE ACCEPT 
message that ISR is activated. 

If the MS is attached for emergency bearer services or if the network has deactivated all non-emergency PDP contexts, 
the network shall indicate in the update result IE in the ROUTING AREA UPDATE ACCEPT message that ISR is not 
activated. 

If the ROUTING AREA UPDATE ACCEPT message contains: 

i) no indication that ISR is activated, an MS supporting SI mode shall set the TIN to "P-TMSI"; or 

ii) an indication that ISR is activated, then: 

if the MS is required to perform tracking area updating for IMS voice termination as specified in annex P. 5, 
the MS shall set the TIN to "P-TMSI"; or 

the MS shall regard the available GUTI and TAI list as valid and registered with the network. If the TIN 
currently indicates "GUTI" and the periodic tracking area update timer T3412 is running, the MS shall set the 
TIN to "RAT-related TMSI". If the TIN currently indicates "GUTI" and the periodic tracking area update 
timer T3412 has already expired, the MS shall set the TIN to "P-TMSI". 

4.7.5.1 .4 Normal and periodic routing area updating procedure not accepted by the 

network 

If the routing area updating cannot be accepted, the network sends a ROUTING AREA UPDATE REJECT message to 
the MS. An MS that receives a ROUTING AREA UPDATE REJECT message, stops timer T3330, and for all causes 
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except #12, #14, #15, #22 and #25 deletes the list of "equivalent PLMNs". If a ROUTING AREA UPDATE REJECT 
message is received, the MS shall stop any ongoing transmission of user data. 

If the routing area update request is rejected due to general NAS level mobility management congestion control, the 
network shall set the GMM cause value to #22 "congestion" and assign a back-off timer T3346. 

The MS shall then take different actions depending on the received reject cause value: 

# 3 (Illegal MS); 

# 6 (Illegal ME); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and enter the state GMM-DEREGISTERED. Furthermore, it shall delete any P-TMSI, P- 
TMSI signature, RAI and GPRS ciphering key sequence number and shall consider the SIM/USIM as invalid for 
GPRS services until switching off or the SIM/USIM is removed. 

If the MS is IMSI attached, the MS shall in addition set the update status to U3 ROAMING NOT ALLOWED, 
shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS operation mode A 
and an RR connection exists, the MS shall abort the RR connection, unless an emergency call is ongoing. The 
SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the SIM/USIM is 
removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
tracking area update procedure is rejected with the EMM cause with the same value. 

NOTE 1 : The possibility to configure a MS so that the radio transceiver for a specific radio access technology is not 
active, although it is implemented in the MS, is out of scope of the present specification. 

# 7 (GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2.9) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM 
is removed. The new state is GMM-DEREGISTERED. 

If the update type is "periodic updating", a GPRS MS operating in MS operation mode A or B in network 
operation mode I is still IMSI attached for CS services in the network, and shall set the timer T3212 to its initial 
value and restart it, if it is not already running. The MS shall then proceed with the appropriate MM specific 
procedure according to the MM service state. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Ust and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
tracking area update procedure is rejected with the EMM cause with the same value. 

# 9 (MS identity cannot be derived by the network); 

The MS shall set the GPRS update status to GU2 NOT UPDATED (and shall store it according to 
subclause 4.1.3.2), enter the state GMM-DEREGISTERED, and shall delete any P-TMSI, P-TMSI signature, 
RAI and GPRS ciphering key sequence number. If the rejected request was not for initiating a PDN connection 
for emergency bearer services, the MS may subsequently,automatically initiate the GPRS attach procedure. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
tracking area update procedure is rejected with the EMM cause with the same value. 

# 10 (Implicitly detached); 

The MS shall change to state GMM-DEREGISTERED.NORMAL-SERVICE. If the rejected request was not for 
initiating a PDN connection for emergency bearer services, the MS shall then perform a new attach procedure. 
The MS should also activate PDP context(s) to replace any previously active PDP contexts. The MS should also 
perform the procedures needed in order to activate any previously active multicast service(s). 

If SI mode is supported in the MS, the MS shall handle the EMM state as specified in 3GPP TS 24.301 [120] for 
the case when the tracking area update procedure is rejected with the EMM cause with the same value. 
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NOTE 2: In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS 
context(s) automatically. 

# 1 1 (PLMN not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2), 
shall reset the routing area updating attempt counter and enter the state GMM-DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMN list". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [14]. 

An MS in GAN mode shall request a PLMN Hst in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in 
3GPP TS 24.301 [120] for the case when the tracking area update procedure is rejected with the EMM cause 
with the same value. 

# 12 (Location area not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2), 
shall reset the routing area updating attempt counter and shall change to state GMM- 
DEREGISTERED.LIMITED-SERVICE. 

The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAJ, TAI list, KSI and tracking area updating attempt counter as specified in 
3GPP TS 24.301 [120] for the case when the tracking area update procedure is rejected with the EMM cause 
with the same value. 

#13 (Roaming not allowed in this location area); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
clause 4.1.3.2) shall reset the routing area updating attempt counter and shall change to state GMM- 
REGISTERED.LIMITED-SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 
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The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
reset the location update attempt counter. The new MM state is MM IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [ 14] . 

An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and 
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the tracking area 
update procedure is rejected with the EMM cause with the same value. 

# 14 (GPRS services not allowed in this PLMN); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM- 
DEREGISTERED. 

The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. A GPRS MS operating 
in MS operation mode C shall perform a PLMN selection instead of a cell selection. 

If the update type is "periodic updating" a GPRS MS operating in MS operation mode A or B in network 
operation mode I shall set the timer T3212 to its initial value and restart it, if it is not already running. 

A GPRS MS operating in MS operation mode A or B in network operation mode II or III, is still IMSI attached 
for CS services in the network. 

As an implementation option, a GPRS MS operating in operation mode A or B may perform the following 
additional action. If no RR connection exists the MS may perform the action immediately. If the MS is operating 
in MS operation mode A and an RR connection exists, the MS may only perform the action when the RR 
connection is subsequently released: 

- The MS may perform a PLMN selection according to 3GPP TS 23. 122 [14]. 

If an MS in GAN mode performs a PLMN selection, it shall request a PLMN hst in GAN (see 

3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23.122 [14]. 

The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause 
is: 

On the "User Controlled PLMN Selector with Access Technology " or. 

On the "Operator Controlled PLMN Selector with Access Technology " list or, 

A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in 
3GPP TS 24.301 [120] for the case when the tracking area update procedure is rejected with the EMM cause 
with the same value. 

# 15 (No Suitable Cells In Location Area); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) shall reset the routing area updating attempt counter and shall change to state GMM- 
REGISTERED.LIMITED-SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 168 ETSI TS 124 008 VI 0.1 0.0 (2013-04) 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
reset the location update attempt counter. The new MM state is MM IDLE. 

The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN 
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121]. 

NOTE 4: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and 
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the tracking area 
update procedure is rejected with the EMM cause with the same value. 

#22 (Congestion); 

If the T3346 value IE is present in the ROUTING AREA UPDATE REJECT message and the value indicates 
that this timer is neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be 
considered as an abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.5.1.5. 

The MS shall abort the routing area updating procedure, reset the routing area updating attempt counter and set 
the GPRS update status to GU2 NOT UPDATED. If the rejected request was not for initiating a PDN connection 
for emergency bearer services, the MS shall change to state GMM-REGISTERED.ATTEMPTING-TO- 
UPDATE. 

The MS shall stop timer T3346 if it is running. 

If the ROUTING AREA UPDATE REJECT message is integrity protected, the MS shall start timer T3346 with 
the value provided in the T3346 value IE. 

If the ROUTING AREA UPDATE REJECT message is not integrity protected, the MS shall start timer T3346 
with a random value from the default range specified in table 1 1.3 a. 

The MS stays in the current serving cell and applies the normal cell reselection process. The routing area 
updating procedure is started, if still necessary, when timer T3346 expires or is stopped. 

If the update type is "periodic updating", a GPRS MS operating in MS operation mode A or B in network 
operation mode I is still IMSI attached for CS services in the network. 

# 25 (Not authorized for this CSG) 

Cause #25 is only applicable in UTRAN lu mode and when received from a CSG cell. Other cases are 
considered as abnormal cases and the specification of the mobile station behaviour is given in 
subclause 4.7.5.1.5. 

If the ROUTING AREA UPDATE REJECT message with cause #25 was received without integrity protection, 
then the MS shall discard the message. 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and store it according to 
subclause 4.1.3.2) and shall reset the routing area updating attempt counter. The state is changed to GMM- 
REGISTERED.LIMITED-SERVICE. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA UPDATE 
REQUEST message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry 
corresponding to this CSG ID and associated PLMN identity from the Allowed CSG list. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA 
UPDATE REQUEST message are contained in the Operator CSG list, the MS shall proceed as specified in 
3GPPTS 23.122 [14] subclause 3.1A. 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 
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If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
reset the location update attempt counter. The new MM state is MM IDLE. 

- The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and 
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the tracking area 
update procedure is rejected with the EMM cause with the same value. 

Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is described in 
subclause 4.7.5.1.5. 

4.7.5.1 .4a Routing area updating procedure for initiating a PDN connection for emergency 

bearer services not accepted by the network (UTRAN lu mode only) 

If the routing area updating request for initiating a PDN connection for emergency bearer services cannot be accepted 
by the network, the MS shall perform the procedures as described in subclause 4.7.5.1.4. Then if the MS is in the same 
selected PLMN where the last routing area updating was attempted, the MS shall: 

a) inform the upper layers. This could result in the MS attempting a CS emergency call (if not already attempted in 
the CS domain) or other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [95] 
that can result in the emergency call being attempted to another IP -CAN; or 

b) detach locally, if not detached already, attempt GPRS attach for emergency bearer services. 

4.7.5.1 .5 Abnormal cases in the MS 

The following abnormal cases can be identified: 

a) Access barred because of access class control 

The routing area updating procedure shall not be started. The MS stays in the current serving cell and applies the 
normal cell reselection process. The procedure is started as soon as possible and if still necessary, i.e. when the 
barred state is removed or because of a cell change. 

b) Lower layer failure without "Extended wait time" received from lower layers before the ROUTING AREA 
UPDATE ACCEPT or ROUTING AREA UPDATE REJECT message is received. 

The procedure shall be aborted and the MS shall proceed as described below, except in the following 
implementation option cases b.l and b.2. 

b. 1) Release of PS signalling connection before the completion of the routing area updating procedure 

The routing area updating procedure shall be initiated again, if the following conditions apply: 

i) The original routing area update procedure was initiated over an existing PS signalling connection; and 

ii) The routing area update procedure was not due to timer T3330 expiry; and 

iii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to 
the PS signalling connection were (e.g. PS authentication procedure, see subclause 4.7.7) received after the 
ROUTING AREA UPDATE REQUEST message was transmitted. 

b.2) RR release in lu mode (i.e. RRC connection release) with, for example, cause "Normal", or "User inactivity" 
or "Direct signalling connection re-establishment" (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) 

The routing area updating procedure shall be initiated again, if the following conditions apply: 

i) The original routing area update procedure was initiated over an existing RRC connection; and 
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ii) The routing area update procedure was not due to timer T3330 expiry; and 

iii) No SECURITY MODE COMMAND message and no Non- Access Stratum (NAS) messages relating to 
the PS signalHng connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the 
ROUTING AREA UPDATE REQUEST message was transmitted. 

NOTE 1 : The RRC connection release cause that triggers the re-initiation of the routing area update procedure is 
implementation specific. 

c) T3330 time-out 

The procedure is restarted four times, i.e. on the fifth expiry of timer T3330, the MS shall abort the procedure 
and, in lu mode, release the PS signalling connection (see 3GPP TS 25.331 [23c]). The MS shall proceed as 
described below. 

d) ROUTING AREA UPDATE REJECT, other causes than those treated in subclause 4.7.5.1.4, and cases of GMM 
cause #22, if considered as abnormal cases according to subclause 4.7.5.1.4 

Upon reception of the cause codes # 95, # 96, # 97, # 99 and #111 the MS should set the routing area updating 
attempt counter to 5. The MS shall proceed as described below. 

e) If a routing area border is crossed, when the MS is in state GMM-ROUTING-AREA-UPDATE-INITIATED, the 
routing area updating procedure shall be aborted and re-initiated immediately. The MS shall set the GPRS update 
status to GU2 NOT UPDATED. 

f) In A/Gb mode, if a cell change occurs within the same RA, when the MS is in state GMM -ROUTING- AREA- 
UPDATE-INITIATED, the cell update procedure is performed, before completion of the routing area updating 
procedure. 

g) Routing area updating and detach procedure collision 

GPRS detach containing detach type"re-attach required" or "re-attach not required": 

If the MS receives a DETACH REQUEST message before the routing area updating procedure has been 
completed, the routing area updating procedure shall be aborted and the GPRS detach procedure shall be 
progressed. If the DETACH REQUEST message contains detach type "re-attach not required" and GMM 
cause #2 "IMSI unknown in HLR", the MS will follow the procedure as described below for the detach type 
"IMSI detach". 

GPRS detach containing detach type "IMSI detach": 

If the MS receives a DETACH REQUEST message before the routing area updating procedure has been 
completed, the routing area updating procedure shall be progressed, i.e. the DETACH REQUEST message 
shall be ignored. 

h) Routing area updating and P-TMSI reallocation procedure collision 

If the MS receives a P-TMSI REALLOCATION COMMAND message before the routing area updating 
procedure has been completed, the P-TMSI reallocation procedure shall be aborted and the routing area updating 
procedure shall be progressed. 

i) "Extended wait time" for PS domain from the lower layers 

If the ROUTING AREA UPDATE REQUEST message contained the NAS signalling low priority indication set 
to "MS is configured for NAS signalling low priority", the MS shall start timer T3346 with the "Extended wait 
time" value. 

In other cases the MS shall ignore the "Extended wait time". 

The MS shall abort the routing area updating procedure, reset the routing area updating attempt counter, stay in 
the current serving cell, set the GPRS update status to GU2 NOT UPDATED, change the state to GMM- 
REGISTERED.ATTEMPTING-TO-UPDATE and apply the normal cell reselection process. 

The routing area updating procedure is started, if still necessary, when timer T3346 expires or is stopped. 

j) Timer T3346 is running 
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The MS shall not start the routing area updating procedure unless: 
the READY timer is running (A/Gb mode); 

- the MS is in PMM-CONNECTED mode (lu mode); 
the MS receives a paging; 

the MS has a PDN connection for emergency bearer services established; or 

the MS is establishing a PDN connection for emergency bearer services. 

The MS stays in the current serving cell and applies the normal cell reselection process. 

The routing area updating procedure is started, if still necessary, when timer T3346 expires or is stopped. 

NOTE 2: It is considered an abnormal case if the MS needs to initiate an routing area updating procedure while 

timer T3346 is running independent on whether timer T3346 was started due to an abnormal case or a non 
successful case. 

If the stored RAI is different to the RAI of the current serving cell or the TIN indicates "GUTI", the MS shall set 
the GPRS update status to GU2 NOT UPDATED and change to state GMM-REGISTERED.ATTEMPTING- 
TO-UPDATE. 

The MS shall proceed as described below. 

In cases b, c, d, e, and g with detach type "re-attach required" or "re-attach not required", the MS shall stop any ongoing 
transmission of user data. 

In cases b, c, d, i and j the MS shall proceed as follows: 

Timer T3330 shall be stopped if still running. The routing area updating attempt counter shall be incremented. 

If the routing area updating attempt counter is less than 5, and the stored RAI is equal to the RAI of the current 
serving cell and the GPRS update status is equal to GUI UPDATED and the TIN does not indicate "GUTI": 

- the MS shall keep the GPRS update status to GUI UPDATED and changes state to GMM- 
REGISTERED.NORMAL-SERVICE. The MS shall start timer T3311. 

If in addition the ROUTING AREA UPDATE REQUEST message indicated "periodic updating", 

- in lu mode, the timer T33 1 1 may be stopped when the MS enters PMM-CONNECTED mode; 

in A/Gb mode, the timer T331 1 may be stopped when the READY timer is started. 

If timer T33 1 1 expires the routing area updating procedure is triggered again. 

If the routing area updating attempt counter is less than 5, and the stored RAI is different to the RAI of the 
current serving cell or the GPRS update status is different to GUI UPDATED or the TIN indicates "GUTI": 

for the cases i and j, the routing area updating procedure is started, if still necessary, when timer T3346 
expires or is stopped; 

- for all other cases, the MS shall start timer T331 1, shall set the GPRS update status to GU2 NOT UPDATED 
and changes state to GMM-REGISTERED.ATTEMPTING-TO-UPDATE. 

If SI mode is supported by the MS, the MS shall in addition handle the EPS update status as specified in 
3GPP TS 24.301 [120] for the abnormal case when a normal or periodic tracking area updating procedure 
fails and the tracking area updating attempt counter is less than 5 and the EPS update status is different from 
EUl UPDATED. 

If the routing area updating attempt counter is greater than or equal to 5: 

- the MS shall start timer T3302, shall delete the list of equivalent PLMNs, shall set the GPRS update status to 
GU2 NOT UPDATED and shall change to state GMM-REGISTERED.ATTEMPTING-TO-UPDATE or 
optionally to GMM-REGISTERED.PLMN-SEARCH(see subclause 4.2.5.1.8) in order to perform a PLMN 
selection according to 3GPP TS 23.122 [14]. 
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If SI mode is supported by the MS, the MS shall in addition handle the EPS update status as specified in 
3GPP TS 24.301 [120] for the abnormal case when a normal or periodic tracking area updating procedure 
fails and the tracking area updating attempt counter is equal to 5. 

4.7.5.1 .6 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) If a lower layer failure occurs before the message ROUTING AREA UPDATE COMPLETE has been received 
from the MS and a P-TMSI and/or PTMSI signature has been assigned, the network shall abort the procedure 
and shall consider both, the old and new P-TMSI and the corresponding P-TMSI signatures as valid until the old 
P-TMSI can be considered as invalid by the network (see subclause 4.7.1.5). During this period the network may 
use the identification procedure followed by a P-TMSI reallocation procedure if the old P-TMSI is used by the 
MS in a subsequent message. 

NOTE: Optionally, paging with IMSI may be used if paging with old and new P-TMSI fails. Paging with IMSI 
causes the MS to re-attach as described in subclause 4.7.9.1. 

b) Protocol error 

If the ROUTING AREA UPDATE REQUEST message has been received with a protocol error, the network 
shall return a ROUTING AREA UPDATE REJECT message with one of the following reject causes: 

#96: Mandatory information element error; 

#99: Information element non-existent or not implemented; 

#100: Conditional IE error; 

#111: Protocol error, unspecified. 

c) T3350 time-out 

On the first expiry of the timer, the network shall retransmit the ROUTING AREA UPDATE ACCEPT message 
and shall reset and restart timer T3350. The retransmission is performed four times, i.e. on the fifth expiry of 
timer T3350, the routing area updating procedure is aborted. Both, the old and the new P-TMSI and the 
corresponding P-TMSI signatures shall be considered as valid until the old P-TMSI can be considered as invalid 
by the network(see subclause 4.7.1.5). During this period the network acts as described for case a above. 
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Figure 4.7.5/1 3GPP TS 24.008: Routing and combined routing area updating procedure 
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d. 1) ROUTING AREA UPDATE REQUEST received after the ROUTING AREA UPDATE ACCEPT message 
has been sent and before the ROUTING AREA UPDATE COMPLETE message is received 

If one or more of the information elements in the ROUTING AREA UPDATE REQUEST message differ from 
the ones received within the previous ROUTING AREA UPDATE REQUEST message, the previously initiated 
routing area updating procedure shall be aborted if the ROUTING AREA UPDATE COMPLETE message has 
not been received and the new routing area updating procedure shall be progressed, or 

- If the information elements do not differ, then the ROUTING AREA UPDATE ACCEPT message shall be 
resent and the timer T3350 shall be restarted if an ROUTING AREA UPDATE COMPLETE message is 
expected. In that case, the retransmission counter related to T3350 is not incremented. 

d.2) More than one ROUTING AREA UPDATE REQUEST received and no ROUTING AREA UPDATE 
ACCEPT or ROUTING AREA UPDATE REJECT message has been sent 

If one or more of the information elements in the ROUTING AREA UPDATE REQUEST message differs from 
the ones received within the previous ROUTING AREA UPDATE REQUEST message, the previously initiated 
routing area updating procedure shall be aborted and the new routing area updating procedure shall be 
progressed; 

If the information elements do not differ, then the network shall continue with the previous routing area updating 
procedure and shall not treat any further this ROUTING AREA UPDATE REQUEST message. 

4.7.5.2 Combined routing area updating procedure 

4.7.5.2.0 General 

Within a combined routing area updating procedure the messages ROUTING AREA UPDATE ACCEPT and 
ROUTING AREA UPDATE COMPLETE carry information for the routing area updating and the location area 
updating. 

4.7.5.2.1 Combined routing area updating procedure initiation 

The combined routing area updating procedure is initiated only by a GPRS MS operating in MS operation modes A or 
B, if the MS is in state GMM-REGISTERED and MM-IDLE, and if the network operates in network operation mode I: 

when a GPRS MS that is IMSI attached for GPRS and non-GPRS services detects a change of the routing area in 
state GMM-REGISTERED and MM-IDLE, unless the MS is configured for "AttachWithlMSI" as specified in 
3GPP TS 24.368 [135] or 3GPP TS 3L102 [112] and is entering a routing area in a new PLMN that is neither 
the registered PLMN nor in the list of equivalent PLMNs; 

when a GPRS MS that is IMSI attached for GPRS services wants to perform an IMSI attach for non-GPRS 

services; 

after termination of a non-GPRS service via non-GPRS channels to update the association if the MS has changed 
the RA during that non-GPRS service transaction; 

after termination of a non-GPRS service via non-GPRS channels to update the association if GPRS services were 
suspended during the non-GPRS service but no resume is received. See 3GPP TS 23.060 [74] subclause 16.2.1; 

after termination of a non-GPRS service via non-GPRS channels to update the association, if the GPRS MS in 
MS operation mode A performed a normal GPRS attach or a normal routing area updating procedure during the 
circuit-switched transaction; 

after a CM SERVICE REJECT message with cause value #4 is received by the mobile station (see 

subclause 4.5.1.1); in this case the update type IE shall be set to "Combined RA/LA updating with IMSI attach"; 

when a GPRS MS needs to update the network with the new MS Radio Access Capability IE; 

when a GPRS MS needs to update the network with a new DRX parameter IE; 

in lu mode, to re-synchronize the PMM mode of MS and network after RRC connection release with cause 
"Directed signalling connection re-establishment", see subclause 4.7.2.5; 
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in lu mode and A/Gb mode, after intersystem change from S 1 mode, and the GMM receives an indication of 
"RRC connection failure" from lower layers due to lower layer failure while in S 1 mode; 

in A/Gb mode, after intersystem change from S 1 mode if the TIN indicates "RAT-related TMSI", but the MS is 
required to perform routing area updating for IMS voice termination as specified in annex P.4; 

- when the MS enters GMM-REGISTERED.NORMAL-SERVICE and the TIN indicates "GUTI" ; 

when the MS supports SRVCC and changes the mobile station classmark 2, mobile station classmark 3 or the 
supported codecs; 

when the MS is configured to use CS fallback and SMS over SGs, or SMS over SGs only, the TIN indicates 
"RAT-related TMSI" and the periodic tracking area update timer T3412 expires; 

when the MS which is configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a 
GERAN or UTRAN cell, the TIN indicates "RAT-related TMSI", and the E-UTRAN deactivate ISR timer 
T3423 is running; 

when the MS which is configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a 
GERAN or UTRAN cell and the E-UTRAN deactivate ISR timer T3423 has expired; 

when due to a manual CSG selection the GPRS MS has selected a CSG cell whose CSG identity and associated 
PLMN identity are not included in the MS's Allowed CSG list or in the MS's Operator CSG list; 

when the MS changes the MS network capability information; 

when the UE's usage setting or the voice domain preference for E-UTRAN change in the MS; 

when the MS activates mobility management for IMS voice termination as specified in annex P.2 and the TIN 
indicates "RAT-related TMSI"; 

upon reception of a paging indication using P-TMSI, if the timer T3346 is running and the MS is in state GMM- 
REGISTERED.ATTEMPTING-TO-UPDATE;or 

when the MS which is configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a 
GERAN or UTRAN cell, after intersystem change from S 1 mode to lu or A/Gb mode not due to CS fallback, 
and the location area of the current cell is different from the location area stored in the MS. 

In A/Gb mode, the routing and location area identification are broadcast on the broadcast channel(s). A combined 
routing area updating procedure shall abort any ongoing GMM procedure. Aborted GMM procedures shall be repeated 
after the combined routing area updating procedure has been successfully performed. The ROUTING AREA UPDATE 
REQUEST message shall always be the first message sent from the MS in the new routing area after routing area 
change. 

In lu mode, the routing and location area identification are broadcast on the broadcast channel(s) or sent to the MS via 
the PS signalling connection. A combined routing area updating procedure shall abort any ongoing GMM procedure. 
Aborted GMM procedures may be repeated after the combined routing area updating procedure has been successfully 
performed. The ROUTING AREA UPDATE REQUEST message shall always be the first GMM message sent from the 
MS in the new routing area after routing area change. 

To initiate a combined routing area updating procedure the MS sends the message ROUTING AREA UPDATE 
REQUEST to the network, starts timer T3330 and changes to state GMM-ROUTING-UPDATING-INITIATED and 
MM LOCATION UPDATING PENDING. The value of the Update type IE in the message shall indicate "combined 
RA/LA updating" unless explicitly specified otherwise. If for the last attempt to update the registration of the location 
area a MM specific procedure was performed, the value of the Update type IE in the ROUTING AREA UPDATE 
REQUEST message shall indicate "combined RA/LA updating with IMSI attach". Furthermore the MS shall include 
the TMSI status IE if no valid TMSI is available. If the MS has stored a valid LAI and the MS supports EMM combined 
procedures, the MS shall include it in the Old location area identification IE in the ROUTING AREA UPDATE 
REQUEST message. 

A GPRS MS in MS operation modes B that is in an ongoing circuit-switched transaction, shall initiate the combined 
routing area updating procedure after the circuit-switched transaction has been released, if the MS has changed the RA 
during the circuit-switched transaction and if the network operates in network operation mode I. 
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A GPRS MS in MS operation mode A shall initiate the combined routing area updating procedure with IMSI attach 
after the circuit-switched transaction has been released, if a normal GPRS attach or a normal routing area updating 
procedure was performed during the circuit-switched transaction and provided that the network operates in network 
operation mode I. 

A GPRS MS in MS operation mode A shall perform the normal routing area update procedure during an ongoing 
circuit-switched transaction. 

In lu mode, if the MS wishes to prolong the established PS signalling connection after the normal routing area updating 
procedure (for example, the MS has any CM application request pending), it may set a follow-on request pending 
indicator on (see subclause 4.7.13). 

In lu mode, when a ROUTING AREA UPDATE REQUEST is received by the SGSN over a new PS signalling 
connection while there is an ongoing PS signalling connection (network is already in mode PMM-CONNECTED) for 
this MS, the network shall progress the routing area update procedure as normal and release the previous PS signalling 
connection when the routing area update procedure has been accepted by the network. 

NOTE: The re-establishment of the radio bearers of active PDP contexts is done as described in subclause 
"Service Request procedure". 

If the combined routing area updating procedure is initiated due to the reception of the paging indication while T3346 is 
running, the "follow-on request pending" indication shall be set to 1 . 

4.7.5.2.2 GMM Common procedure initiation 

The network may initiate GMM common procedures, e.g. the GMM authentication and ciphering procedure. 

4.7.5.2.3 Combined routing area updating procedure accepted by the network 

Depending on the value of the update result IE received in the ROUTING AREA UPDATE ACCEPT message, two 
different cases can be distinguished; 

Case 1) The update result IE value indicates "combined RA/LA": Routing and location area updating is 
successful; 

Case 2) The update result IE value indicates "RA only": Routing area updating is successful, but location area 
updating is not successful. 

A ROUTING AREA UPDATE COMPLETE message shall be returned to the network if the ROUTING AREA 
UPDATE ACCEPT message containsany of: 

- a P-TMSI and/or a TMSI; 

- Receive N-PDU Numbers (see 3GPP TS 44.065 [78] and 3GPP TS 25.322 [19b]); or 

a request for the provision of Inter RAT handover information or E-UTRAN inter RAT handover information or 
both. 

If Receive N-PDU Numbers were included, the Receive N-PDU Numbers that are valid in the MS shall be included in 
the ROUTING AREA UPDATE COMPLETE message. 

If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover 
information the MS shall return a ROUTING AREA UPDATE COMPLETE message including the Inter RAT 
handover information IE or the E-UTRAN inter RAT handover information IE or both, as applicable, to the network. 

In lu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has 
indicated "follow-on request pending" in ROUTING AREA UPDATE REQUEST message) the network shall indicate 
the "follow-on proceed" in the ROUTING AREA UPDATE ACCEPT message. If the network wishes to release the PS 
signalling connection, the network shall indicate "no follow-on proceed" in the ROUTING AREA UPDATE ACCEPT 

message. 

After that in lu mode, the mobile station shall act according to the follow-on proceed flag included in the Update result 
information element in the ROUTING AREA UPDATE ACCEPT message (see subclause 4.7.13). 
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If the network supports CS Fallback, and the mobile station has indicated support of EMM combined procedures in MS 
network capabiUty, the network shall indicate in the Update result IE in the ROUTING AREA UPDATE ACCEPT 
message that ISR is not activated. 

4.7.5.2.3.1 Combined routing area updating successful 

The description for normal routing area update as specified in subclause 4.7.5.1.3 shall be followed. In addition, the 
following description for location area updating applies. 

The handling at the receipt of the ROUTING AREA UPDATE ACCEPT depends on the value received in the update 
result IE as specified below. 

The TMSI reallocation may be part of the combined routing area updating procedure. The TMSI allocated is then 
included in the ROUTING AREA UPDATE ACCEPT message together with the location area identification (LAI). 
The network shall, in this case, change to state GMM-COMMON-PROCEDURE-INITIATED and shall start the timer 
T3350 as described in subclause 4.7.6. 

The MS, receiving a ROUTING AREA UPDATE ACCEPT message, stores the received location area identification, 
stops timer T3330, enters state MM IDLE, reset the location update attempt counter and sets the update status to Ul 
UPDATED. If the ROUTING AREA UPDATE ACCEPT message contains an IMSI, the mobile station is not allocated 
any TMSI, and shall delete any TMSI accordingly. If the ROUTING AREA UPDATE ACCEPT message contains a 
TMSI, the MS shall use this TMSI as new temporary identity. The MS shall delete its old TMSI and shall store the new 
TMSI. In this case, an ROUTING AREA UPDATE COMPLETE message is returned to the network. If neither a TMSI 
nor an IMSI has been included by the network in the ROUTING AREA UPDATE ACCEPT message, the old TMSI, if 
any is available, shall be kept. 

Any timer used for triggering the location updating procedure (e.g. T321 1, T3212) shall be stopped if running. 

The network receiving a ROUTING AREA UPDATE COMPLETE message stops timer T3350, changes to GMM- 
REGISTERED state and considers the new TMSI as valid. 

4.7.5.2.3.2 Combined routing area updating successful for GPRS services only 

Apart from the actions on the routing area updating attempt counter, the description for normal routing area update as 
specified in subclause 4.7.5. L3 shall be followed. In addition, the following description for location area updating 
applies. 

The MS receiving the ROUTING AREA UPDATE ACCEPT message takes one of the following actions depending on 
the reject cause: 

#2 (IMSI unknown in HLR); 

The MS shall stop timer T3330 if still running and shall reset the routing area updating attempt counter. The MS 
shall set the update status to U3 ROAMING NOT ALLOWED and shall delete any TMSI, LAI and ciphering 
key sequence number. The MS shall enter state GMM-REGISTERED.NORMAL-SERVICE. The new MM state 
is MM IDLE. The SIM/USIM shall be considered as invalid for non-GPRS services until switching off or the 
SIM/USIM is removed. 

#16 (MSC temporarily not reachable); 

#17 (Network failure); or 

#22 (Congestion). 

The MS shall change to state GMM-REGISTERED.ATTEMPTING-TO-UPDATE-MM. Timer T3330 shall be 
stopped if still running. The routing area updating attempt counter shall be incremented. If the routing area 
updating attempt counter is less than 5, and the stored RAI is equal to the RAI of the current serving cell and the 
GMM update status is equal to GUI UPDATED: 

- the MS shall keep the GMM update status GUI UPDATED and changes state to GMM- 

REGISTERED.ATTEMPTING-TO-UPDATE-MM. The MS shall start timer T331 1. When timer T3311 
expires the combined routing area update procedure indicating "combined RA/LA updating with IMSI 
attach" is triggered again. 
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If the routing area updating attempt counter is greater than or equal to 5: 

- the MS shall start timer T3302 and shall change to state GMM-REGISTERED.ATTEMPTING-TO- 
UPDATE-MM; 

a GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific procedure; 
a GPRS MS operating in MS operation mode B may then proceed with appropriate MM specific procedures. 
The MM sublayer shall act as in network operation mode II or III (depending whether a PCCCH is present) 
as long as the combined GMM procedures are not successful and no new RA is entered. The new MM state 
is MM IDLE. 

Other reject cause values and the case that no GMM cause IE was received are considered as abnormal cases. The 
combined routing area updating shall be considered as failed for GPRS and non-GPRS services. The specification of the 
MS behaviour in those cases is specified in subclause 4.7.5.2.5. 

4.7.5.2.4 Combined routing area updating not accepted by the network 

If the combined routing area updating cannot be accepted, the network sends a ROUTING AREA UPDATE REJECT 
message to the MS. An MS that receives a ROUTING AREA UPDATE REJECT message stops timer T3330, enters 
state MM IDLE, and for all causes except #12, #14, #15, #22 and #25 deletes the Hst of "equivalent PLMNs". If a 
ROUTING AREA UPDATE REJECT message is received, the MS shall stop any ongoing transmission of user data. 

If the routing area update request is rejected due to general NAS level mobility management congestion control, the 
network shall set the GMM cause value to #22 "congestion" and assign a back-off timer T3346. 

The MS shall then take different actions depending on the received reject cause; 

# 3 (Illegal MS); 

# 6 (Illegal ME), or 

# 8 (GPRS services and non GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED and the update status to U3 
ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2) and enter the state GMM- 
DEREGISTERED. Furthermore, it shall delete any P-TMSI, P-TMSI signature, TMSI, RAI, LAI, ciphering key 
sequence number and GPRS ciphering key sequence number and shall consider the SIM/USIM as invalid for 
GPRS and non GPRS services until switching off or the SIM/USIM is removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
combined tracking area update procedure is rejected with the EMM cause with the same value. 

# 7 (GPRS services not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM 
is removed. The new state is GMM-DEREGISTERED. If in the MS the timer T3212 is not already running, the 
timer shall be set to its initial value and restarted. 

A GPRS MS operating in MS operation mode A or B in network operation mode I which is already IMSI 
attached for CS services, is still IMSI attached for CS services in the network. 

A GPRS MS operating in MS operation mode A or B in network operation mode I shall proceed with the 
appropriate MM specific procedure according to the MM service state. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
combined tracking area update procedure is rejected with the EMM cause with the same value. 

# 9 (MS identity cannot be derived by the network); 

The MS shall set the GPRS update status to GU2 NOT UPDATED (and shall store it according to 
subclause 4.1.3.2), enter the state GMM-DEREGISTERED, and shall delete any P-TMSI, P-TMSI signature. 
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RAJ and GPRS ciphering key sequence number. If the rejected request was not for initiating a PDN connection 
for emergency bearer services, the MS may subsequently, automatically initiate the GPRS attach procedure. 

A GPRS MS operating in MS operation mode A or B in network operation mode I, is still IMSI attached for CS 
services in the network. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
combined tracking area update procedure is rejected with the EMM cause with the same value. 

# 10 (Implicitly detached); 

A GPRS MS operating in MS operation mode A or B in network operation mode I, is IMSI detached for both 
GPRS and CS services in the network. 

The MS shall change to state GMM-DEREGISTERED.NORMAL-SERVICE. If the rejected request was not for 
initiating a PDN connection for emergency bearer services, the MS shall then perform a new attach procedure. 
The MS should also activate PDP context(s) to replace any previously active PDP context(s). The MS should 
also perform the procedures needed in order to activate any previously active multicast service(s). 

If SI mode is supported in the MS, the MS shall handle the EMM state as specified in 3GPP TS 24.301 [120] for 
the case when the combined tracking area update procedure is rejected with the EMM cause with the same value. 

NOTE 1 : In some cases, user interaction may be required and then the MS cannot activate the PDP/MBMS 
context(s) automatically. 

# 1 1 (PLMN not allowed); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED and the update status to U3 
ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2) and enter the state GMM- 
DEREGISTERED. Furthermore, it shall delete any P-TMSI, P-TMSI signature, TMSI, RAI, LAI, ciphering key 
sequence number GPRS ciphering key sequence number, and reset the routing area updating attempt counter and 
the location update attempt counter. 

The MS shall store the PLMN identity in the "forbidden PLMN Ust". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall then perform a PLMN selection according to 3GPP TS 23.122 [14]. 

An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN 
selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in 
3GPP TS 24.301 [120] for the case when the combined tracking area update procedure is rejected with the EMM 
cause with the same value. 

# 12 (Location area not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2), 
shall reset the routing area updating attempt counter and shall change to state GMM- 
DEREGISTERED.LIMITED-SERVICE. 

The MS shall in addition set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI 
and ciphering key sequence number and shall reset the location update attempt counter. The new MM state is 
MM IDLE. 

The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode. 
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If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAJ, TAI list, KSI and tracking area updating attempt counter as specified in 
3GPP TS 24.301 [120] for the case when the combined tracking area update procedure is rejected with the EMM 
cause with the same value. 

#13 (Roaming not allowed in this location area); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
clause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM- 
REGISTERED.LIMITED-SERVICE. 

The MS shall in addition set the update status to U3 ROAMING NOT ALLOWED and shall reset the location 
update attempt counter. The new MM state is MM IDLE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall perform a PLMN selection according to 3GPP TS 23.122 [14]. 

The MS shall indicate the Update type IE "combined RA/LA updating with IMSI attach" when performing the 
routing area updating procedure following the PLMN selection. 

An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN 
selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and 
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the combined 
tracking area update procedure is rejected with the EMM cause with the same value. 

# 14 (GPRS services not allowed in this PLMN); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored, 
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM- 
DEREGISTERED. If in the MS the timer T3212 is not already running, the timer shall be set to its initial value 
and restarted. 

The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. 

A GPRS MS operating in MS operation mode A or B in network operation mode I which is already IMSI 
attached for CS services, is still IMSI attached for CS services in the network. 

A GPRS MS operating in MS operation mode A or B in network operation mode I shall proceed with the 
appropriate MM specific procedure according to the MM service state. 

As an implementation option, a GPRS MS operating in operation mode A or B may perform a PLMN selection 
according to 3GPP TS 23.122 [14]. 

If an MS in GAN mode performs a PLMN selection, it shall request a PLMN Hst in GAN (see 

3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23. [14]. 

The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause 
is: 

On the "User Controlled PLMN Selector with Access Technology " or. 

On the "Operator Controlled PLMN Selector with Access Technology " list or, 

A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in 
3GPP TS 24.301 [120] for the case when the combined tracking area update procedure is rejected with the EMM 
cause with the same value. 
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# 15 (No Suitable Cells In Location Area); 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
clause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM- 
REGISTERED.LIMITED-SERVICE. 

The MS shall in addition set the update status to U3 ROAMING NOT ALLOWED and shall reset the location 
update attempt counter. The new MM state is MM IDLE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

The MS shall search for a suitable cell in another location area in the same PLMN according to 
3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode. 

The MS shall indicate the Update type IE "combined RA/LA updating with IMSI attach" when performing the 
routing area updating procedure. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and 
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the combined 
tracking area update procedure is rejected with the EMM cause with the same value. 

#22 (Congestion); 

If the T3346 value IE is present in the ROUTING AREA UPDATE REJECT message and the value indicates 
that this timer is neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be 
considered as an abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.5.2.5. 

The MS shall abort the routing area updating procedure, reset the routing area updating attempt counter and set 
the GPRS update status to GU2 NOT UPDATED. If the rejected request was not for initiating a PDN connection 
for emergency bearer services, the MS shall change to state GMM-REGISTERED.ATTEMPTING-TO- 
UPDATE. 

The MS shall stop timer T3346 if it is running. 

If the ROUTING AREA UPDATE REJECT message is integrity protected, the MS shall start timer with the 
value provided in the T3346 value IE. 

If the ROUTING AREA UPDATE REJECT message is not integrity protected, the ME shall start timer T3346 
with a random value from the default range specified in table 1 1.3 a. 

The MS stays in the current serving cell and applies the normal cell reselection process. The routing area 
updating procedure is started, if still necessary, when timer T3346 expires or is stopped. 

#25 (Not authorized for this CSG) 

Cause #25 is only applicable in UTRAN lu mode and when received from a CSG cell. Other cases are 
considered as abnormal cases and the specification of the mobile station behaviour is given in 
subclause 4.7.5.2.5. 

If the ROUTING AREA UPDATE REJECT message with cause #25 was received without integrity protection, 
then the MS shall discard the message. 

The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and store it according to 
subclause 4.1.3.2) and shall reset the routing area updating attempt counter. The state is changed to GMM- 
REGISTERED.LIMITED-SERVICE. 

If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA UPDATE 
REQUEST message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry 
corresponding to this CSG ID and associated PLMN identity from the Allowed CSG list. 
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If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA UPDATE 
REQUEST message are contained in the Operator CSG list, the MS shall proceed as specified in 
3GPPTS 23.122 [14] subclause 3.1 A. 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
reset the location update attempt counter. The new MM state is MM IDLE. 

- The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and 
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the combined 
tracking area update procedure is rejected with the EMM cause with the same value. 

Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is described in 
subclause 4.7.5.2.5. 

4.7.5.2.5 Abnormal cases in the MS 

The MS shall proceed as follows: 

If the combined routing area update was successful for GPRS services only and the ROUTING AREA UPDATE 
ACCEPT message contained a cause value not treated in subclause 4.7.5.2.3.2 or the GMM Cause IE is not 
included in the message, the MS shall follow the procedure specified in subclause 4.7.5.1.5 step d) with the 
following modification; 

otherwise, the abnormal cases specified in subclause 4.7.5.1.5 apply with the following modification. 

If the GPRS routing area updating attempt counter is incremented according to subclause 4.7.5.1.5 the next actions 
depend on the Location Area Identities (stored on SIM/US IM and the one of the current serving cell) and the value of 
the routing area updating attempt counter. 

if the update status is Ul UPDATED, and the stored LAI is equal to the one of the current serving cell and the 
routing area updating attempt counter is smaller than 5, then the mobile station shall keep the update status to Ul 
UPDATED, the new MM state is MM IDLE substate NORMAL SERVICE; 

if the routing area updating attempt counter is smaller than 5 and, additionally, the update status is different from 
Ul UPDATED or the stored LAI is different from the one of the current serving cell, the mobile station shall 
delete any LAI, TMSI, ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs 
and set the update status to U2 NOT UPDATED. The MM state remains MM LOCATION UPDATING 
PENDING; or 

if the routing area updating attempt counter is greater or equal to 5, the mobile station shall delete any LAI, 
TMSI, ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs and set the update 
status to U2 NOT UPDATED. 

A GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific procedure; a 
GPRS MS operating in MS operation mode B may then proceed with appropriate MM specific procedures. 
The MM sublayer shall act as in network operation mode II or III (depending whether a PCCCH is present) as 
long as the combined GMM procedures are not successful and no new RA is entered. The new MM state is MM 
IDLE substate ATTEMPTING TO UPDATE or optionally MM IDLE substate PLMN SEARCH in order to 
perform a PLMN selection according to 3GPP TS 23.122 [14]. 

4.7.5.2.6 Abnormal cases on the network side 

The abnormal cases specified in subclause 4.7.5.1.6 apply with the exceptions for cases a and c in which in addition to 
the P-TMSI and P-TMSI signature the old TMSI shall be considered occupied until the new TMSI is used by the MS in 
a subsequent message. 
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4.7.6 P-TMSI reallocation procedure 



A temporary mobile station identity for GPRS services, the Packet-TMSI (P-TMSI), is used for identification within the 
radio interface signalling procedures. The structure of the P-TMSI is specified in 3GPP TS 23.003 [10]. The P-TMSI 
has significance only within a routing area. Outside the routing area it has to be combined with the routing area 
identification (RAI) to provide for an unambiguous identity. 

The purpose of the P-TMSI reallocation procedure is to provide identity confidentiality, i.e. to protect a user against 
being identified and located by an intruder (see 3GPP TS 42.009 [5] and 3GPP TS 43.020 [13]). 

Usually, P-TMSI reallocation is performed at least at each change of a routing area. (Such choices are left to the 
network operator). 

The reallocation of a P-TMSI is performed by the unique procedure defined in this subclause. This procedure can only 
be initiated by the network in state GMM -REGISTERED. 

P-TMSI can also be implicitly reallocated in the attach or routing area updating procedures. The implicit reallocation of 
a P-TMSI is described in the corresponding subclause s. 

NOTE: Normally, the P-TMSI reallocation will take place in conjunction with another GMM procedure, e.g. at 
routing area updating (see 3GPP TS 29.002 [37]). 

4.7.6.1 P-TMSI reallocation initiation by the network 

The network initiates the P-TMSI reallocation procedure by sending a P-TMSI REALLOCATION COMMAND 

message to the MS and starts the timer T3350. 

The P-TMSI REALLOCATION COMMAND message contains a new combination of P-TMSI, RAI and optionally a 
P-TMSI signature allocated by the network. 

The network may suspend the transmission of user data during the P-TMSI reallocation procedure. 

4.7.6.2 P-TMSI reallocation completion by the MS 

Upon receipt of the P-TMSI REALLOCATION COMMAND message, the MS stores the Routing Area Identifier 
(RAI) and the P-TMSI and sends a P-TMSI REALLOCATION COMPLETE message to the network. 

If a P-TMSI signature is present in the P-TMSI REALLOCATION COMMAND message, the MS shall store the new 
P-TMSI signature and shall if available delete the old P-TMSI signature. If no P-TMSI signature is present in the P- 
TMSI REALLOCATION COMMAND message, the old P-TMSI signature, if available, shall be kept. 

4.7.6.3 P-TMSI reallocation completion by the network 

Upon receipt of the P-TMSI REALLOCATION COMPLETE message, the network stops the timer T3350 and 
considers both the old and the new P-TMSI and the corresponding P-TMSI signatures as valid until the old P-TMSI can 
be considered as invalid by the network (see subclause 4.7.1.5). 

In A/Gb mode, the GMM layer shall notify the LLC layer that the P-TMSI has been changed (see 
3GPP TS 44.064 [78a]). 

4.7.6.4 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) Lower layer failure 

If a lower layer failure is detected before the P-TMSI REALLOCATION COMPLETE message is received, the 
old and the new P-TMSI shall be considered as occupied until the old P-TMSI can be considered as invalid by 
the network (see subclause 4.7.1.5). 

During this period the network: 
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may first use the old P-TMSI for paging for an implementation dependent number of paging attempts in the 
case of network originated transactions. Upon response from the MS, the network may re-initiate the P-TMSI 
reallocation. If no response is received to the paging attempts, the network may use the new P-TMSI for 
paging for an implementation dependent number of paging attempts. Upon response from the MS the 
network shall consider the new P-TMSI as valid and the old P-TMSI as invalid. If no response is received to 
the paging attempts, the network may use the IMSI for paging, for an implementation dependent number of 
paging attempts; 

NOTE: Paging with IMSI causes the MS to re-attach as described in subclause 4.7.9. 1. 

shall consider the new P-TMSI as valid if it is used by the MS (see subclause 4.7. 1 .5); or 

may use the identification procedure followed by a new P-TMSI reallocation if the MS uses the old P-TMSI. 

b) Expiry of timer T3350 

The P-TMSI reallocation procedure is supervised by the timer T3350. The network shall, on the first expiry of 
timer T3350, reset and restart timer T3350 and shall retransmit the P-TMSI REALLOCATION COMMAND. 
This retransmission is repeated four times, i.e. on the fifth expiry of timer T3350, the network shall abort the 
reallocation procedure and shall follow the rules for case a as described above. 

c) P-TMSI reallocation and GPRS attach procedure collision 

If the network receives an ATTACH REQUEST message before the ongoing P-TMSI reallocation procedure has 
been completed the network shall proceed with the GPRS attach procedure after deletion of the GMM context. 

d) P-TMSI reallocation and an MS initiated GPRS detach procedure collision 

If the network receives a DETACH REQUEST message before the ongoing P-TMSI reallocation procedure has 
been completed, the network shall abort the P-TMSI reallocation procedure and shall progress the GPRS detach 
procedure. 

e) P-TMSI reallocation and a routing area updating procedure collision 

If the network receives a ROUTING AREA UPDATE REQUEST message before the ongoing P-TMSI 
reallocation procedure has been completed, the network shall abort the P-TMSI reallocation procedure and shall 
progress the routing area updating procedure. The network may then perform a new P-TMSI reallocation. 

f) P-TMSI reallocation and a service request procedure collision 

If the network receives a SERVICE REQUEST message before the ongoing P-TMSI reallocation procedure 
procedure has been completed, the network shall progress both procedures. 

If there are different new P-TMSI included in subsequent P-TMSI REALLOCATION COMMAND messages, due to 
an aborted or repeated P-TMSI reallocation procedure, the MS always regards the newest and its existing P-TMSI as 
valid for the recovery time. 



MS Network 

P-TMSI REALLOCATION COMMAND 



P-TMSI REALLOCATION COMPLETE 



Start T3350 
Stop T3350 



Figure 4.7.6/1 3GPP TS 24.008: P-TMSI reallocation procedure 
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4.7.7 Authentication and cipinering procedure 

4.7.7a Authentication and ciphering procedure used for UMTS authentication 

challenge. 

The purpose of the authentication and ciphering procedure is fourfold (see 3GPP TS 33.102 [5a]): 

to permit the network to check whether the identity provided by the MS is acceptable or not; 

to provide parameters enabling the MS to calculate a new GPRS UMTS ciphering key and a new GPRS UMTS 
integrity key; 

to let the network set the GSM ciphering mode (ciphering /no ciphering) and GSM ciphering algorithm; and 

to permit the mobile station to authenticate the network. 

In lu mode, and in the case of a UMTS authentication challenge, the authentication and ciphering procedure can be used 
for authentication only. 

The cases in which the authentication and ciphering procedure shall be used are defined in 3GPP TS 33.102 [5a] and 
3GPPTS 42.009 [5]. 

The authentication and ciphering procedure is always initiated and controlled by the network. However, in the case of a 
UMTS authentication challenge, there is the possibility for the MS to reject the network. 

The MS shall support the UMTS authentication challenge, if a USIM is inserted. 

The authentication and ciphering procedure can be used for either: 
authentication only; 

setting of the GSM ciphering mode and the GSM ciphering algorithm only; or 
authentication and the setting of the GSM ciphering mode and the GSM ciphering algorithm. 

In A/Gb mode, the network should not send any user data during the authentication and ciphering procedure. 

A UMTS security context is established in the MS and the network when a UMTS authentication challenge is 
performed in A/Gb mode or in lu mode. After a successful UMTS authentication, the GPRS UMTS ciphering key, the 
GPRS UMTS integrity key, the GPRS GSM ciphering key and the GPRS ciphering key sequence number, are stored 
both in the network and the MS. Furthermore, in A/Gb mode both the ME and the network may derive and store a 
GPRS GSM Kci28 as part of the UMTS security context as described in the subclause 4.7.7.3a. 

4.7.7b Authentication and ciphering procedure used for GSM authentication 

challenge 

The purpose of the authentication and ciphering procedure is threefold (see 3GPP TS 43.020 [13]): 
to permit the network to check whether the identity provided by the MS is acceptable or not; 
to provide parameters enabling the MS to calculate a new GPRS GSM ciphering key; and 
to let the network set the GSM ciphering mode (ciphering/no ciphering) and GSM ciphering algorithm. 

The authentication and ciphering procedure can be used for either: 
authentication only; 

setting of the GSM ciphering mode and the GSM ciphering algorithm only; or 
authentication and the setting of the GSM ciphering mode and the GSM ciphering algorithm. 

The cases in which the authentication and ciphering procedure shall be used are defined in 3GPP TS 42.009 [5]. 
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In A/Gb mode, the authentication and ciphering procedure is always initiated and controlled by the network. It shall be 
performed in a non ciphered mode because of the following reasons: 

- the network cannot decipher a ciphered AUTHENTICATION_AND_CIPHERING RESPONSE from an 
unauthorised MS and put it on the black list; and 

to be able to define a specific point in time from which on a new GPRS GSM ciphering key should be used 
instead of the old one. 

GSM authentication challenge shall be supported by a ME supporting GERAN or UTRAN. 

In A/Gb mode, the network should not send any user data during the authentication and ciphering procedure. 

A GSM security context is established in the MS and the network when a GSM authentication challenge is performed in 
A/Gb mode or in lu mode. However, in lu mode the MS shall not accept a GSM authentication challenge, if a USIM is 
inserted. After a successful GSM authentication challenge, the GPRS GSM ciphering key and the GPRS ciphering key 
sequence number, are stored both in the network and the MS. 

4.7.7c Change of the ciphering algorithm at PS Handover 

For PS handover to A/Gb mode (see subclause 10.5.1.14 and 3GPP TS 44.060 [76]) the network shall either assign a 
GSM ciphering algorithm to be used in the target cell or deactivate ciphering in the target cell. The MS shall start to use 
the new GSM ciphering algorithm or deactivate ciphering upon an indication from the lower layers that the PS 
handover procedure has been successfully completed (see 3GPP TS 44.060 [76]) 

After PS handover to lu mode (see 3GPP TS 25.331 [23c] and 3GPP TS 44.1 18 [1 11]) the network shall activate 
integrity protection and shall either assign a ciphering algorithm to be used in the target cell or deactivate ciphering in 
the target cell, using the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). 

If the GSM ciphering algorithm is changed at PS handover and the routing area updating procedure triggered by the PS 
handover procedure is not accepted by the network, the MS shall delete any GPRS ciphering key sequence number and 
proceed as specified in subclauses 4.7.5.1.4 and 4.7.5.2.4. If the routing area updating procedure fails, because the radio 
resources assigned in the new cell are released before the MS receives a ROUTING AREA UPDATE ACCEPT 
message, the MS shall delete any GPRS ciphering key sequence number and proceed as specified in 
subclauses 4.7.5.1.5 itemb and 4.7.5.2.5, respectively. 

4.7.7.1 Authentication and ciphering initiation by the network 

The network initiates the authentication and ciphering procedure by transferring an 

AUTHENTICATION_AND_CIPHERING REQUEST message across the radio interface and starts timer T3360. The 
AUTHENTICATION_AND_CIPHERING REQUEST message shall contain all parameters necessary to calculate the 
response parameters when authentication is performed (see 3GPP TS 43.020 [13] and 3GPP TS 33.102 [5a]). 

If authentication is requested, then the AUTHENTICATION. AND_CIPHERING REQUEST message shall contain 
either; 

In a GSM authentication challenge, the GPRS ciphering key sequence number and the RAND, or 

In a UMTS authentication challenge, the GPRS ciphering key sequence number, the RAND and the AUTN. 

In A/Gb mode, if authentication is not requested, then the AUTHENTICATION_AND_CIPHERING REQUEST 
message shall not contain neither the GPRS ciphering key sequence number, the RAND nor the AUTN. 

In A/Gb mode, if ciphering is requested, in a GSM authentication challenge or in a UMTS authentication challenge, 
then the AUTHENTICATION_AND_CIPHERING REQUEST message shall indicate the GPRS GSM ciphering 
algorithm. 

The network includes the A&C reference number information element in the 

AUTHENTICATION_AND_CIPHERING REQUEST message. Its value is chosen in order to link an 
AUTHENTICATION_AND_CIPHERING REQUEST in a RA with its RESPONSE. The A&C reference number value 
might be based on the RA Colour Code value. 

Additionally, the network may request the MS to include its IMEISV in the AUTHENTICATION_AND_CIPHERING 
RESPONSE message. 
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4.7.7.2 Authentication and ciphering response by the MS 

In A/Gb mode, a MS that is attached to GPRS shall be ready to respond upon an 
AUTHENTICATION_AND_CIPHERING REQUEST message at any time. 

In UMTS, an MS that is attached to GPRS shall be ready to respond upon an 
AUTHENTICATION_AND_CIPHERING REQUEST message at any time whilst a PS signalUng connection exists. 

If a SIM is inserted in the MS, the MS shall ignore the Authentication Parameter AUTN IE if included in the 
AUTHENTICATION_AND_CIPHERING REQUEST message and perform the GSM authentication challenge. It shall 
not perform the authentication of the network described in subclause 4.7.7.5. 1. 

In a GSM authentication challenge, if the AUTHENTICATION_AND_CIPHERING REQUEST message includes the 
authentication parameters RAND and GPRS CKSN, then upon receipt of the message, the MS processes the challenge 
information and sends an AUTHENTICATION_AND_CIPHERING RESPONSE message to the network. The value of 
the received A&C reference number information element shall be copied into the A&C reference number information 
element in the AUTHENTICATION_AND_CIPHERING RESPONSE message. A GSM authentication challenge will 
result in the SIM/USIM passing a SRES and a GPRS GSM ciphering key to the ME. The new GPRS GSM ciphering 
key calculated from the challenge information shall overwrite the previous one and any previously stored GPRS UMTS 
ciphering and GPRS UMTS integrity keys shall be deleted. The calculated GSM ciphering key shall be stored on the 
SIM/USIM together with the GPRS ciphering key sequence number before the 
AUTHENTICATION_AND_CIPHERING RESPONSE message is transmitted. 

In a UMTS authentication challenge, if the AUTHENTICATION_AND_CIPHERING REQUEST message includes the 
UMTS authentication parameters GPRS CKSN, RAND and AUTN, then upon receipt of the message, the MS verifies 
the AUTN parameter and if this is accepted, the MS processes the challenge information and sends an 
AUTHENTICATION_AND_CIPHERING RESPONSE message to the network. The value of the received A&C 
reference number information element shall be copied into the A&C reference number information element in the 
AUTHENTICATION_AND_CIPHERING RESPONSE message. A UMTS authentication challenge will result in the 
USIM passing a RES, a GPRS UMTS ciphering key, a GPRS UMTS integrity key and a GPRS GSM ciphering key to 
the ME. The new GPRS UMTS ciphering key, GPRS UMTS integrity key and GPRS GSM ciphering key calculated 
from the challenge information shall overwrite the previous ones. The new GPRS UMTS ciphering key, GPRS UMTS 
integrity key and GPRS GSM ciphering key shall be stored on the USIM together with the GPRS ciphering key 
sequence number before the AUTHENTICATION_AND_CIPHERING RESPONSE message is transmitted. 
Furthermore, in A/Gb mode if a GEA ciphering algorithm that requires a 128-bit ciphering key is taken into use, then a 
new GPRS GSM Kci28 shall also be calculated as described in the subclause 4.7.7.3a. 

In lu mode, an MS capable of UMTS only shall ignore the Ciphering Algorithm IE in the 

AUTHENTICATION_AND_CIPHERING REQUEST message. An MS capable of both lu mode and A/Gb mode shall 
store the received value in the Ciphering Algorithm IE in the AUTHENTICATION_AND_CIPHERING REQUEST 
message in order to use it at an inter system change from lu mode to A/Gb mode. 

If the AUTHENTICATION_AND_CIPHERING REQUEST message does not include neither the GSM authentication 
parameters (RAND and GPRS CKSN) nor the UMTS authentication parameters (RAND, AUTN and GPRS CKSN), 
then upon receipt of the message, the MS replies by sending an AUTHENTICATION_AND_CIPHERING RESPONSE 
message to the network. 

In A/Gb mode, the GMM layer shall notify the LLC layer if ciphering shall be used or not and if yes which GSM 
ciphering algorithm and GPRS GSM ciphering key that shall be used (see 3GPP TS 44.064 [78a]). 

A ME supporting UMTS authentication challenge shall support the following procedure: 

In order to avoid a synchronisation failure, when the mobile station receives an 

AUTHENTICATION_AND_CIPHERING REQUEST message, the mobile station shall store the received RAND 
together with the RES returned from the USIM in the volatile memory and associate it with the PS domain. When the 
MS receives a subsequent AUTHENTICATION_AND_CIPHERING REQUEST message, if the stored RAND value 
for the PS domain is equal to the new received value in the AUTHENTICATION_AND_CIPHERING REQUEST 
message, then the mobile station shall not pass the RAND to the USIM, but shall immediately send the 
AUTHENTICATION_AND_CIPHERING RESPONSE message with the stored RES for the PS domain. If, for the PS 
domain, there is no valid stored RAND in the mobile station or the stored RAND is different from the new received 
value in the AUTHENTICATION_AND_CIPHERING REQUEST message, the mobile station shall pass the RAND to 
the USIM, shall override any previously stored RAND and RES with the new ones and start, or reset and restart timer 
T3316. 
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The RAND and RES values stored in the mobile station shall be deleted and timer T3316, if running, shall be stopped: 

- upon receipt of a SECURITY MODE COMMAND (lu mode only), 

SERVICE_ACCEPT (lu mode only), 

SERVICE_REJECT (lu mode only), 

ROUTING_AREA_UPDATE_ACCEPT 

or AUTHENTICATION_AND_CIPHERING REJECT message; 

upon expiry of timer T33 16; or 

- if the mobile station enters the GMM states GMM-DEREGISTERED or GMM-NULL. 

4.7.7.3 Authentication and ciphering completion by the network 

Upon receipt of the AUTHENTICATION AND CIPHERING RESPONSE message, the network stops the timer T3360 
and checks the vahdity of the response (see 3GPP TS 43.020 [13] and 3GPP TS 33.102 [5a]). For this, it may use the 
A&C reference number information element within the AUTHENTICATION AND CIPHERING RESPONSE message 
to determine whether the response is correlating to the last request that was sent. 

In A/Gb mode, in the case of an established GSM security context, the GMM layer shall notify the LLC sublayer if 
ciphering shall be used or not. Furthermore, if ciphering shall be used, then the GMM layer shall also notify the LLC 
sublayer which GEA algorithm and GPRS GSM ciphering key that shall be used (see 3GPP TS 44.064 [78a]). 

In A/Gb mode, in the case of an established UMTS security context, the GMM layer shall notify the LLC sublayer if 
ciphering shall be used or not. Furthermore, if ciphering shall be used, then the GMM layer shall also notify the LLC 
sublayer which GEA algorithm and which ciphering key (i.e. GPRS GSM ciphering key or GPRS GSM Kci28) that shall 
be used (see 3GPP TS 44.064 [78a]). If the network has selected a GEA ciphering algorithm that requires a 128-bit 
ciphering key, then the ME shall derive a GPRS GSM Kci28 as described in the subclause 4.7.7.3a. 

Upon receipt of the AUTHENTICATION AND CIPHERING FAILURE message, the network stops the timer T3360. 
In Synch failure case, the core network may renegotiate with the HLR/AuC and provide the MS with new 
authentication parameters. 

4.7.7.3a 128-bit packet-switched GSM ciphering key 

The ME and the network may derive and store a 128-bit packet-switched GSM key or GPRS GSM Kci28 from an 
established UMTS security context. If the GPRS GSM Kci28 exits, then it is also part of the UMTS security context. 

The ME with a USIM in use shall compute a new GPRS GSM Kci28 using the GPRS UMTS ciphering key and the 
GPRS UMTS integrity key from an established UMTS security context as specified in 3GPP TS 33.102 [5a]. The new 
GPRS GSM Kci28 shall be stored only in the ME. The ME shall overwrite the existing GPRS GSM Kci28 with the new 
GPRS GSM Kci28. The ME shall delete the GPRS GSM Kci28 at switch off, when the USIM is disabled as well as 
under the conditions identified in the subclause 4.1.3.2 and 4.7.7.4. The ME with a USIM in use shall apply the GPRS 
GSM Kci28 when in A/Gb mode a GEA ciphering algorithm that requires a 128-bit ciphering key is taken into use. 

The network shall compute the GPRS GSM Kci28 using the GPRS UMTS integrity key and the GPRS UMTS ciphering 
key from an established UMTS security context as specified in 3GPP TS 33.102 [5a] only when in A/Gb mode a GEA 
ciphering algorithm that requires a 128-bit ciphering key is to be used. 

4.7.7.4 GPRS ciphering key sequence number 

The security parameters for authentication and ciphering are tied together in sets. 

In a GSM authentication challenge, from a challenge parameter RAND both the authentication response parameter 
SRES and the GPRS GSM ciphering key can be computed given the secret key associated to the IMSI. 

In a UMTS authentication challenge, from a challenge parameter RAND, the authentication response parameter RES 
and the GPRS UMTS ciphering key and the GPRS UMTS integrity key can be computed given the secret key 
associated to the IMSI. Furthermore, in the USIM a GPRS GSM ciphering key can be computed from the GPRS UMTS 
integrity key and the GPRS UMTS ciphering key by means of an unkeyed conversion function. Furthermore, in A/Gb 
mode if a GEA ciphering algorithm that requires a 128-bit ciphering key is taken into use, then a GPRS GSM Kci28 
shall also be calculated as described in the subclause 4.7.7.3a. 
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In order to allow start of ciphering on a logical link without authentication, GPRS ciphering key sequence numbers are 
introduced. 

The GPRS ciphering key sequence number is managed by the network such that the AUTHENTICATION 
AND CIPHERING REQUEST message contains the GPRS ciphering key sequence number allocated to the GPRS 
GSM ciphering key (in case of a GSM authentication challenge) or the GPRS UMTS ciphering key and the GPRS 
UMTS integrity key (in case of a UMTS authentication challenge) which may be computed from the RAND parameter 
carried in that message. 

If an authentication and ciphering procedure has been completed successfully and a GPRS ciphering key sequence 
number is stored in the network, the network shall include a different GPRS ciphering key sequence number in the 
AUTHENTICATION AND CIPHERING REQUEST message when it intiates a new authentication and ciphering 
procedure. 

The MS stores the GPRS ciphering key sequence number with the GPRS GSM ciphering key (in case of a GSM 
authentication challenge) and the GPRS UMTS ciphering key and the GPRS UMTS integrity key (in case of a UMTS 
authentication challenge), and includes the corresponding GPRS ciphering key sequence number in the ROUTING 
AREA UPDATE REQUEST, SERVICE REQUEST and ATTACH REQUEST messages. 

If the GPRS ciphering key sequence number is deleted, the associated GPRS GSM ciphering key, GPRS UMTS 
ciphering key, GPRS UMTS integrity key and GPRS GSM Kcizs shall be deleted if any (i.e. the established GSM 
security context or the UMTS security context is no longer valid). 

In lu mode, the network may choose to start ciphering and integrity checking with the stored GPRS UMTS ciphering 

key and the stored GPRS UMTS integrity key (under the restrictions given in 3GPP TS 42.009 [5] and 

3GPP TS 33.102 [5a]) if the stored GPRS ciphering key sequence number and the one given from the MS are equal. 

In A/Gb mode, the network may choose to start ciphering with the stored GPRS GSM ciphering key or GPRS GSM 
Kci28 (under the restrictions given in 3GPP TS 42.009 [5]) if the stored GPRS ciphering key sequence number and the 
one given from the MS are equal and the previously negotiated ciphering algorithm is known and supported in the 
network. When ciphering is requested at GPRS attach, the authentication and ciphering procedure shall be performed 
since the MS does not store the ciphering algorithm at detach. 

NOTE 1: The decision of starting ciphering with the GPRS GSM ciphering key or the GPRS GSM Kci28 depends 
on whether the network indicates in the AUTHENTICATION AND CIPHERING REQUEST message a 
GEA ciphering algorithm which requires a 64 or 128-bit ciphering key as specified in 
3GPPTS 33.102 [5a]. 

Upon GPRS attach, if ciphering is to be used, an AUTHENTICATION AND CIPHERING REQUEST message shall 
be sent to the MS to start ciphering. 

If the GPRS ciphering key sequence number stored in the network does not match the GPRS ciphering key sequence 
number received from the MS in the ATTACH REQUEST message, then the network should authenticate the MS. 

In A/Gb mode, the MS starts ciphering after sending the AUTHENTICATION AND CIPHERING RESPONSE 
message. The network starts ciphering when a valid AUTHENTICATION AND CIPHERING RESPONSE is received 
from the MS. 

In lu mode, the MS starts ciphering and integrity checking according to the conditions specified in specification 
3GPPTS 25.331 [23c]. 

In A/Gb mode, as an option, the network may decide to continue ciphering without sending an AUTHENTICATION 
AND CIPHERING REQUEST message after receiving a ROUTING AREA UPDATE REQUEST message with a valid 
GPRS ciphering key sequence number. Both the MS and the network shall use the latest ciphering parameters. The 
network starts ciphering when sending the ciphered ROUTING AREA UPDATE ACCEPT message to the MS. The MS 
starts ciphering after receiving a valid ciphered ROUTING AREA UPDATE ACCEPT message from the network. 

NOTE 2: In some specifications the term KSI (Key Set Identifier) is used instead of the term GPRS ciphering key 
sequence number. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 189 ETSI TS 124 008 VI 0.1 0.0 (2013-04) 

4.7.7.5 Authentication not accepted by the network 

If authentication and ciphering fails, i.e. if the response is not valid, the network considers whether the MS has used the 
P-TMSI or the IMSI for identification. 

If the P-TMSI has been used, the network may decide to initiate the identification procedure. If the IMSI given 
by the MS differs from the one the network had associated with the P-TMSI, the authentication should be 
restarted with the correct parameters. If the IMSI provided by the MS is the expected one (i.e. authentication has 
really failed), the network should proceed as described below. 

If the IMSI has been used, or the network decides not to try the identification procedure, an 
AUTHENTICATION AND CIPHERING REJECT message should be transferred to the MS. 

Upon receipt of an AUTHENTICATION AND CIPHERING REJECT message, the MS shall set the GPRS update 
status to GU3 ROAMING NOT ALLOWED and shall delete the P-TMSI, P-TMSI signature, RAI and GPRS ciphering 
key sequence number stored. If available, also the TMSI, LAI and ciphering key sequence number shall be deleted and 
the update status shall be set to U3 ROAMING NOT ALLOWED. The SIM/USIM shall be considered as invalid until 
switching off or the SIM/USIM is removed. 

If SI mode is supported by the MS, the MS shall in addition handle the EMM parameters EMM state, EPS update 
status, last visited registered TAI, TAJ list, GUTI and KSIasme as specified in 3GPP TS 24.301 [120] for the case when 
an EPS authentication is not accepted by the network. 

If the AUTHENTICATION AND CIPHERING REJECT message is received, the MS shall abort any GMM procedure, 
shall stop the timers T3310, T3317 and T3330 (if running) and shall enter state GMM-DEREGISTERED. 

In UTRAN lu mode, depending on local regulations or operator preference for emergency bearer services, if the MS has 
a PDN connection for emergency bearer services established or is establishing a PDN connection for emergency bearer 
services, the SGSN need not follow the procedures specified for the authentication failure in the present subclause, the 
SGSN can continue with the ongoing GMM specific procedure or Session Management procedure. Upon completion of 
the GMM procedure or Session management procedure, the SGSN shall deactivate all non-emergency PDP contexts, if 
any, by initiating a PDP context deactivation procedure. The network shall consider the MS to be attached for 
emergency bearer services only. 

4.7.7.5.1 Authentication not accepted by the MS 

In a UMTS authentication challenge, the authentication procedure is extended to allow the MS to check the authenticity 
of the core network. Thus allowing, for instance, detection of false base station. 

Following a UMTS authentication challenge, the MS may reject the core network, on the grounds of an incorrect 
AUTN parameter (see 3GPP TS 33.102 [5a]). This parameter contains two possible causes for authentication failure: 

a) MAC code failure 

If the MS considers the MAC code (supplied by the core network in the AUTN parameter) to be invalid, it shall send a 
AUTHENTICATION AND CIPHERING FAILURE message to the network, with the GMM cause 'MAC failure'. The 
MS shall then follow the procedure described in subclause 4.7.7.6 (f). 

b) SQN failure 

If the MS considers the SQN (supplied by the core network in the AUTN parameter) to be out of range, it shall 
send a AUTHENTICATION AND CIPHERING FAILURE message to the network, with the GMM cause 
'Synch failure' and the re-synchronization token AUTS provided by the USIM (see 3GPP TS 33.102 [5a]). 
The MS shall then follow the procedure described in subclause 4.7.7.6 (g). 

In lu mode, an MS with a USIM inserted shall reject the authentication challenge if no Authentication Parameter AUTN 
IE was present in the AUTHENTICATION REQUEST message (i.e. a GSM authentication challenge has been received 
when the MS expects a UMTS authentication challenge). In such a case, the MS shall send the AUTHENTICATION 
AND CIPHERING FAILURE message to the network, with the GMM cause 'GSM authentication unacceptable'. The 
MS shall then follow the procedure described in subclause 4.7.7.6 (f). 

If the MS returns an AUTHENTICATION_AND_CIPHERING_FAILURE message to the network, the MS shall 
delete any previously stored RAND and RES and shall stop timer T3316, if running. 
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If the MS has a PDN connection for emergency bearer services established or is estabhshing such a PDN connection, 
additional MS requirements are specified in subclause 4.7.7.6, under "for items f and g". 

4.7.7.6 Abnormal cases 

The following abnormal cases can be identified: 

a) Lower layer failure 

Upon detection of a lower layer failure before the AUTHENTICATION AND CIPHERING RESPONSE is 
received, the network shall abort the procedure. 

b) Expiry of timer T3360 

The network shall, on the first expiry of the timer T3360, retransmit the AUTHENTICATION AND 
CIPHERING REQUEST and shall reset and start timer T3360. This retransmission is repeated four times, i.e. on 
the fifth expiry of timer T3360, the procedure shall be aborted. 

c) Collision of an authentication and ciphering procedure with a GPRS attach procedure 

If the network receives an ATTACH REQUEST message before the ongoing authentication procedure has been 
completed and no GPRS attach procedure is pending on the network (i.e. no ATTACH ACCEPT/REJECT 
message has to be sent as an answer to an ATTACH REQUEST message), the network shall abort the 
authentication and ciphering procedure and proceed with the new GPRS attach procedure. 

d) Collision of an authentication and ciphering procedure with a GPRS attach procedure when the authentication 
and ciphering procedure has been caused by a previous GPRS attach procedure 

If the network receives an ATTACH REQUEST message before the ongoing authentication procedure has been 
completed and a GPRS attach procedure is pending (i.e. an ATTACH ACCEPT/REJECT message has still to be 
sent as an answer to an earlier ATTACH REQUEST message), then: 

If one or more of the information elements in the ATTACH REQUEST message differs from the ones 
received within the previous ATTACH REQUEST message, the network shall not treat the authentication 
any further and proceed with the GPRS attach procedure; or 

If the information elements do not differ, then the network shall not treat any further this new ATTACH 
REQUEST. 

Collision of an authentication and ciphering procedure with a GPRS detach procedure 

GPRS detach containing cause "power off: 

If the network receives a DETACH REQUEST message before the ongoing authentication and ciphering 
procedure has been completed, the network shall abort the authentication and ciphering procedure and shall 
progress the GPRS detach procedure. 

GPRS detach containing other causes than "power off": 

If the network receives a DETACH REQUEST message before the ongoing authentication and ciphering 
procedure has been completed, the network shall complete the authentication and ciphering procedure and 
shall respond to the GPRS detach procedure as described in subclause 4.7.4. 
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e) Collision of an authentication and ciphering procedure with a routing area updating procedure 

If the network receives a ROUTING AREA UPDATE REQUEST message before the ongoing authentication 
procedure has been completed, the network shall progress both procedures. 



MS Network 

AUTHENTICATION AND CIPHERING REQUEST 

< Start T3360 



AUTHENTICATION AND CIPHERING RESPONSE 



Stop T3360 



AUTHENTICATION AND CIPHERING REJECT 



Figure 4.7.7/1 3GPP TS 24.008: Authentication and ciphiering procedure 

(f) Authentication failure (GMM cause #18 "MAC failure" or #21 "GSM authentication unacceptable") 

The MS shall send an AUTHENTICATION & CIPHERING FAILURE message, with GMM cause 'MAC 
failure' or 'GSM authentication unacceptable' according to subclause 4.7.7.5.1, to the network and start timer 
T3318. Furthermore, the MS shall stop any of the retransmission timers that are running (e.g. T3310, T3321, 
T3330 or T33 17). Upon the first receipt of an AUTHENTICATION & CIPHERING FAILURE message from 
the MS with GMM cause 'MAC failure' or 'GSM authentication unacceptable' the network may initiate the 
identification procedure described in subclause 4.7.8. This is to allow the network to obtain the IMSI from the 
MS. The network may then check that the P-TMSI originally used in the authentication challenge corresponded 
to the correct IMSI. Upon receipt of the IDENTITY REQUEST message from the network, the MS shall send 
the IDENTITY RESPONSE message. 

NOTE: Upon receipt of an AUTHENTICATION & CIPHERING FAILURE message from the MS with reject 
cause "MAC failure" or "GSM authentication unacceptable", the network may also terminate the 
authentication procedure (see subclause 4.7.7.5). 

If the P-TMSI/IMSI mapping in the network was incorrect, the network should respond by sending a new 
AUTHENTICATION & CIPHERING REQUEST message to the MS. Upon receiving the new 
AUTHENTICATION & CIPHERING REQUEST message from the network, the MS shall stop timer T3318, if 
running, and then process the challenge information as normal. 

If the network is validated successfully (an AUTHENTICATION & CIPHERING REQUEST message that 
contains a valid SQN and MAC is received), the MS shall send the AUTHENTICATION & CIPHERING 
RESPONSE message to the network and shall start any retransmission timers (e.g. T3310, T3321, T3330 or 
T3317), if they were running and stopped when the MS received the first failed AUTHENTICATION AND 
CIPHERING REQUEST message. 

If the MS receives the second AUTHENTICATION AND CIPHERING REQUEST while T3318 is running and 

the MAC value cannot be resolved; or 

the message was received in UMTS and contains a GSM authentication challenge, 

the MS shall follow the procedure specified in this subclause (f), starting again from the beginning. If the SQN is 
invalid, the MS shall proceed as specified in (g). 

It can be assumed that the source of the authentication challenge is not genuine (authentication not accepted by 
the MS) if any of the following occurs: 

- after sending the AUTHENTICATION & CIPHERING FAILURE message with GMM cause 'MAC failure' 
or 'GSM authentication unacceptable' the timer T3318 expires; 

- the MS detects any combination of the authentication failures: "MAC failure", "invahd SQN", and "GSM 
authentication unacceptable", during three consecutive authentication challenges. The authentication 
challenges shall be considered as consecutive only, if the authentication challenges causing the second and 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



192 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



third authentication failure are received by the MS, while the timer T3318 or T3320 started after the previous 
authentication failure is running. 

When it has been deemed by the MS that the source of the authentication challenge is not genuine 
(authentication not accepted by the MS), the MS shall behave as described in subclause 4.7.7.6.1. 



Start T33 18 
StopT3318 


MS Network 
AUTHENTICATION & CIPHERING REQUEST 


^ Start T3360 

AUTH & CIPH FAILURE (cause='MAC failure' or 

'GSM authentication unacceptable') ^Stop T3360 


IDENTITY REQUEST ^^^^^^33^^ 


IDENTITY RESPONSE (IMSI) ^^^ ^33^^ 


AUTHENTICATION & CIPHERING REQUEST g^^^.^ ^jg^Q 


AUTHENTICATION & CIPHERING RESPONSE Stop T3360 





Figure 4.7.7a/1 3GPP TS 24.008: Authentication failure cause "IVIAC failure" or "GSM authentication 

unacceptable" 

(g) Authentication failure (GMM cause #19 "Synch failure"): 

The MS shall send an AUTHENTICATION & CIPHERING FAILURE message, with the GMM cause "Synch 
failure", to the network and start the timer T3320. Furthermore, the MS shall stop any of the retransmission 
timers that are running (e.g. T3310, T3321, T3330 or T3317). Upon the first receipt of an AUTHENTICATION 
& CIPHERING message from the MS with the GMM cause "synch failure", the network shall use the returned 
AUTS parameter from the authentication & ciphering failure parameter IE in the AUTHENTICATION & 
CIPHERING FAILURE message, to re-synchronise. The re-synchronisation procedure requires the SGSN to 
delete all unused authentication vectors for that IMSI and obtain new vectors from the HLR. When re- 
synchronisation is complete, the network shall initiate the authentication & ciphering procedure. Upon receipt of 
the AUTHENTICATION & CIPHERING REQUEST message, the MS shall stop timer T3320, if running. 

NOTE: Upon receipt of two consecutive AUTHENTICATION & CIPHERING FAILURE messages from the 

MS with reject cause "synch failure", the network may terminate the authentication procedure by sending 
an AUTHENTICATION & CIPHERING REJECT message. 

If the network is validated successfully (a new AUTHENTICATION & CIPHERING REQUEST message is 
received which contains a valid SQN and MAC) while T3320 is running, the MS shall send the 
AUTHENTICATION & CIPHERING RESPONSE message to the network and shall start any retransmission 
timers (i.e. T3310, T3321, T3330 or T3317), if they were running and stopped when the MS received the first 
failed AUTHENTICATION AND CIPHERING REQUEST message. 

If the MS receives the second AUTHENTICATION & CIPHERING REQUEST while T3320 is running and 

the MAC value cannot be resolved; or 

the message was received in lu mode and contains a GSM authentication challenge, 

the MS shall proceed as specified in (f). If the SQN is invalid, the MS shall follow the procedure specified in this 
subclause (g), starting again from the beginning. 
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The MS shall deem that the network has failed the authentication check and behave as described in 
subclause 4.7.7.6.1, if any of the following occurs: 

the timer T3320 expires; 

- the MS detects any combination of the authentication failures: "MAC failure", "invalid SQN", and "GSM 
authentication unacceptable", during three consecutive authentication challenges. The authentication 
challenges shall be considered as consecutive only, if the authentication challenges causing the second and 
third authentication failure are received by the MS, while the timer T3318 or T3320 started after the previous 
authentication failure is running. 



MS Network 

AUTHENTICATION & CIPHERING REQUEST ^^^ ^^360 



AUTH & CIPH FAILURE (cause='Synch failure') Stop T3360 
Start T3320 ^p^^^^^^ 

AUTHENTICATION & CIPHERING REQUEST Re-synch 

Stop T3320 ^ with HLR 

AUTHENTICATION & CIPHERING RESPONSE 

► 



Figure 4.7.7b/1 3GPP TS 24.008: Authentication failure cause Synch failure' 



For items f and g: 



Depending on local requirements or operator preference for emergency bearer services, if the MS has a PDN 
connection for emergency bearer services established or is establishing such a PDN connection, the SGSN need 
not follow the procedures specified for the authentication failure specified in the present subclause and shall 
continue using the current security context, if any. The SGSN shall deactivate all non-emergency PDP contexts, 
if any, by initiating a PDP context deactivation procedure. If there is an ongoing session management procedure, 
the SGSN shall deactivate all non-emergency PDP contexts upon completion of the session management 
procedure. The network shall consider the MS to be attached for emergency bearer services only. 

If an MS has a PDN connection for emergency bearer services established or is establishing such a PDN 
connection when timer T3318 or T3320 expires, the MS shall not deem that the network has failed the 
authentication check and not behave as described in subclause 4.7.7.6.1. Instead the MS shall continue using the 
current security context, if any. The MS shall deactivate all non-emergency PDP contexts, if any, by initiating a 
PDP context deactivation procedure. If there is an ongoing session management procedure, the MS shall 
deactivate all non-emergency PDP contexts upon completion of the session management procedure. The MS 
shall consider itself to be attached for emergency bearer services only. 



4.7.7.6.1 



MS behaviour towards a network that has failed the authentication procedure 



If the MS deems that the network has failed the authentication check, then it shall request RR or RRC to release the RR 
connection and the PS signalling connection, if any, and bar the active cell or cells (see 3GPP TS 25.331 [23c] and 
3GPP TS 44.018 [84]). The MS shall start any retransmission timers (i.e. T3310, T3321, T3330 or T3317), if they were 
running and stopped when the MS received the first AUTHENTICATION AND CIPHERING REQUEST message 
containing an invalid MAC or invalid SQN, or no AUTN when a UMTS authentication challenge was expected. 



4.7.7.7 



Use of established security contexts 



In A/Gb mode, in the case of an established GSM security context, the GPRS GSM ciphering key shall be taken into 
use by the MS before the AUTHENTICATION AND CIPHERING RESPONSE message is transmitted. 
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In A/Gb mode, in the case of an established UMTS security context, and if the network indicates in the 
AUTHENTICATION AND CIPHERING REQUEST message to the MS that a GEA ciphering algorithm that requires 
a 64-bit ciphering key shall be taken into use, then the GPRS GSM ciphering key shall be taken into use by the MS 
before the AUTHENTICATION AND CIPHERING RESPONSE message is transmitted. The network shall derive a 
GPRS GSM ciphering key from the GPRS UMTS ciphering key and the GPRS UMTS integrity key, by using the 
conversion function named "c3" defined in 3GPP TS 33.102 [5a]. 

In A/Gb mode, in the case of an established UMTS security context, and if the network indicates in the 
AUTHENTICATION AND CIPHERING REQUEST message to the MS that a GEA ciphering algorithm that requires 
a 128-bit ciphering key shall be taken into use, then the MS shall take the following actions: 

if authentication is not requested and a GEA ciphering algorithm that requires 64-bit ciphering key is in use, the 
MS shall take into use the GPRS GSM Kci28 derived by the ME from the GPRS UMTS ciphering key and GPRS 
UMTS integrity key of the established UMTS security context in use (see 3GPP TS 33.102 [5a]) before the 
AUTHENTICATION AND CIPHERING RESPONSE message is transmitted;. 

if authentication is not requested and a GEA ciphering algorithm that requires 128-bit ciphering key is in use, the 
GPRS GSM Kci28 of the established UMTS security context in use still applies; 

otherwise, the MS shall take into use the GPRS GSM Kci28 derived by the ME from the GPRS UMTS ciphering 
key and the GPRS UMTS integrity key provided by the USIM during the latest successful authentication 
procedure (see subclause 4.7.7.3a) before the AUTHENTICATION AND CIPHERING RESPONSE message is 
transmitted. 

In A/Gb mode, in the case of an established UMTS security context, and if the network indicates in the 
AUTHENTICATION AND CIPHERING REQUEST message to the MS that a GEA ciphering algorithm that requires 
a 128-bit ciphering key shall be taken into use, then the network shall derive a GPRS GSM KC|28 (see 
subclause 4.7.7.3a). 

In A/Gb mode, if during an ongoing, already ciphering protected RR connection, the network initiates a new 
Authentication and ciphering procedure, the new GPRS GSM ciphering key or GPRS GSM KC|28 shall be taken into 
use by the MS before the AUTHENTICATION AND CIPHERING RESPONSE message is transmitted. In case of 
inter-system change to lu mode after receipt of the AUTHENTICATION AND CIPHERING REQUEST message, the 
MS and the network shall take the new keys into use immediately after the inter-system change. 

In lu mode, in the case of an established GSM security context, the ME shall derive a GPRS UMTS ciphering key and a 
GPRS UMTS integrity key from the GPRS GSM ciphering key by using the conversion functions named "c4" and "c5" 
defined in 3GPP TS 33.102 [5a]. The derived GPRS UMTS ciphering key and GPRS UMTS integrity key shall be 
taken into use by the MS when a valid SECURITY MODE COMMAND message indicating PS domain is received 
during an RR connection (the definition of a valid SECURITY MODE COMMAND message is given in 
3GPP TS 25.331 [23c]). The network shall derive a GPRS UMTS ciphering key and a GPRS UMTS integrity key from 
the GPRS GSM ciphering key by using the conversion functions named "c4" and "c5" defined in 3GPP TS 33.102 [5a]. 

In lu mode, in the case of an estabhshed UMTS security context, the GPRS UMTS ciphering key and the GPRS UMTS 
integrity key shall be taken into use by the MS when a valid SECURITY MODE COMMAND message indicating PS 
domain is received during a PS signalling connection (the definition of a valid SECURITY MODE COMMAND 
message is given in 3GPP TS 25.331 [23c]). 

In lu mode, if the MS received a vahd SECURITY MODE COMMAND message indicating PS domain in lu mode or a 
valid AUTHENTICATION AND CIPHERING REQUEST message in A/Gb mode before the network initiates a new 
authentication and ciphering procedure and establishes a new GSM/UMTS security context, the new GPRS UMTS 
ciphering key and GPRS UMTS integrity key are taken into use by the MS, when a new valid SECURITY MODE 
COMMAND message indicating PS domain is received during the PS signalling connection. In case of inter-system 
change to A/Gb mode, the MS and the network shall take the new keys into use immediately after the inter-system 
change. 

4.7.7.8 Handling of keys at intersystem change from lu mode to A/Gb mode 

At an inter-system change from lu mode to A/Gb mode, ciphering may be started (see 3GPP TS 44.064 [78a]) without 
any new authentication and ciphering procedure. Deduction of the appropriate security key for ciphering in A/Gb mode, 
depends on the current GSM/UMTS security context stored in the MS and the network. 

The ME shall handle the GPRS GSM ciphering key and a potential GPRS GSM Kci28 according to table 4.7.7.8.1. 
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In the case of an established GSM security context, before any initial GMM message is sent in the new cell in A/Gb 
mode, the GMM layer in the MS shall notify the LLC layer if ciphering shall be used or not. If ciphering shall be used, 
then the GPRS GSM ciphering key and the applicable GEA ciphering algorithm according to the stored Ciphering 
Algorithm IE in the MS shall also be indicated to the LLC layer (see 3GPP TS 44.064 [78a]). 

In the case of an established UMTS security context, before any initial GMM message is sent in the new cell in A/Gb 
mode, the GMM layer in the MS shall notify the LLC layer if ciphering shall be used or not. If ciphering shall be used, 
then the GPRS GSM ciphering key or GPRS GSM Kci28 and the applicable GEA ciphering algorithm according to the 
stored Ciphering Algorithm IE in the MS shall also be indicated to the LLC layer (see 3GPP TS 44.064 [78a]). If the 
network has selected a GEA-algorithm that requires a 128-bit ciphering key, then the ME shall apply a GPRS GSM 
Kci28 derived from the GPRS UMTS ciphering key and the GPRS UMTS integrity key of the estabUshed UTMS 
security context as specified in 3GPP TS 33.102 [5a]. 

Table 4.7.7.8.1/3GPP TS 24.008: Inter-system change from lu mode to A/Gb mode 



Security context established in MS and 
network in lu mode 


At inter-system change to A/Gb mode: 


GSIVI security context 


An ME shall apply the GPRS GSM ciphering key that was 
received from the GSM security context created in the SIM/USIM 
during the latest successful authentication procedure. 


UIVITS security context 


If a GEA algorithm is taken into use that requires a 64-bit long 
ciphering key, then an ME shall apply the GPRS GSM ciphering 
key that was derived by the USIM from the GPRS UMTS 
ciphering key and the GPRS UMTS integrity key during the latest 
successful authentication procedure. 
If a GEA algorithm is taken into use that requires a 128-bit 
ciphering key, then an ME shall apply the GPRS GSM Kci28 
derived by the ME from the GPRS UMTS ciphering key and the 
GPRS UMTS integrity key (see 3GPP TS 33.102 [5a]) provided 
by the USIM during the lastest successful authentication 
procedure (see subclause 4.7.7.3a). 



NOTE: A USIM with UMTS security context, passes the GPRS UMTS ciphering key, the GPRS UMTS integrity 
key and the derived GPRS GSM ciphering key to the ME independent on the current radio access being 
UTRAN or GERAN. 



4.7.7.9 



Handling of keys at intersystem change from A/Gb mode to lu mode 



At an inter-system change from A/Gb mode to lu mode, ciphering and integrity may be started (see 
3GPP TS 25.331 [23c]) without any new authentication and ciphering procedure. Deduction of the appropriate security 
keys for ciphering and integrity check in lu mode, depends on the current GSM/UMTS security context stored in the 
MS and the network. 

The ME shall handle the GPRS UMTS ciphering key and the GPRS UMTS integrity key according to table 4.7.7.9.1. 
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Table 4.7.7.9. 1/3GPP TS 24.008: Inter-system change from A/Gb mode to lu mode 



Security context established in MS and 
network in A/Gb mode 


At inter-system change to lu mode: 


GSM security context 


An ME shall derive the GPRS UMTS ciphering key and the 
GPRS UMTS integrity key from the GPRS GSM ciphering key 
that was provided by the SIM/USIM during the latest successful 
authentication procedure. The conversion functions named "c4" 
and "c5" in 3GPP TS 33.1 02 [5a] are used for this purpose. 


UMTS security context 


An ME shall apply the GPRS UMTS ciphering key and the GPRS 
UMTS integrity key that were received from the UMTS security 
context created in the USIM during the latest successful 
authentication procedure. 



NOTE: A USIM with UMTS security context, passes the GPRS UMTS ciphering key, the GPRS UMTS integrity 
key and the derived GPRS GSM ciphering key to the ME independent on the current radio access being 
UTRAN or GERAN. 

4.7.7.10 Handling of keys at intersystem change from S1 mode to lu mode or A/Gb 
mode 

At an inter-system change from S 1 mode to lu mode, ciphering and integrity may be started (see 
3GPP TS 25.331 [23c]) without any new authentication and ciphering procedure. At an inter-system change from 
SI mode to A/Gb mode, ciphering may be started (see 3GPP TS 44.064 [78a]) without any new authentication and 
ciphering procedure. Deduction of the appropriate security keys for ciphering and integrity check in lu mode or for 
ciphering in A/Gb mode, depends on the current EPS security context or the UMTS security context for the PS domain 
stored in the MS and the network. 

The ME shall handle the GPRS UMTS ciphering key, the GPRS UMTS integrity key, the GPRS GSM ciphering key 
and a potential GPRS GSM Kc^g according to table 4.7.7.10.1, table 4.7.7.10.2 and table 4.7.7.10.3. 

Table 4.7.7.10.1/3GPP TS 24.008: Inter-system change from SI mode to lu mode or A/Gb mode in 

connected mode. 



Security context established in MS and 
network 


At inter-system change to lu mode or /VGb mode in connected 
mode 


EPS security context 


An ME shall derive the UMTS security keys GPRS UMTS 
ciphering key (OK') and GPRS UMTS integrity key (IK') from 
Kasme and the NAS downlink COUNT value as specified in 
3GPP TS 33.401 [119]. The ME shall use the derived UMTS 
security keys to derive the GPRS GSM ciphering key using the 
"c3" conversion function as specified in 3GPP TS 33.102 [119]. 
At inter-system change from SI mode to lu mode, the ME shall 
apply the new derived GPRS UMTS integrity key and GPRS 
UMTS ciphering key. 

At inter-system change from SI mode to /VGb mode, the ME 
shall apply the new derived GPRS GSM ciphering key. 
Furthermore, the ME shall replace an already established UMTS 
security context for the PS domain, if any, in the USIM. The MS 
shall in addition handle the STARTps value as specified in 
3GPP TS 25.331 [23c]. 

At inter-system change from SI mode to /VGb mode, if a GEA 
algorithm is taken into use that requires a 64-bit long ciphering 
key, then an ME shall apply the derived GPRS GSM ciphering 
key. 

At inter-system change from SI mode to /VGb mode, if a GEA 
algorithm is taken into use that requires a 128-bit long ciphering 
key, then an ME shall apply the derived GPRS GSM Kci28 that 
was derived by the ME from the derived UMTS security keys 
(see subclause 4.7.7.3a). 
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NOTE 1: For the case in table 4.7.7.10.1, because of deriving a new UMTS security context for the PS domain, a 
new GPRS GSM ciphering key needs to be derived from the new derived UMTS security keys (i.e. CK' 
and IK'). Note that the new GPRS GSM ciphering key is also part of the new UMTS security context for 
the PS domain, and therefore any old GPRS GSM ciphering key stored in the USIM and in the ME 
belongs to an old UMTS security context for the PS domain and can no longer be taken into use. 

Table 4.7.7.1 0.2/3GPP TS 24.008: Inter-system change from SI mode to lu mode or A/Gb mode in idle 

mode when the TIN indicates "GUTI". 



Security context established in MS and 
network 


At inter-system cliange to lu mode or A/Gb mode in idle mode 
when the TIN indicates "GUTI" 


EPS security context 


An ME shall derive the UMTS security keys GPRS UMTS 
ciphering key (OK') and GPRS UMTS integrity key (IK') from 
Kasme and the NAS uplink COUNT value as specified in 
3GPP TS 33.401 [119]. The ME shall use the derived UMTS 
security keys to derive the GPRS GSM ciphering key using the 
"c3" conversion function as specified in 3GPP TS 33.102 [5a]. 
At inter-system change from SI mode to lu mode, the ME shall 
apply the new derived GPRS UMTS integrity key and GPRS 
UMTS ciphering key. 

At inter-system change from SI mode to A/Gb mode, the ME 
shall apply the new derived GPRS GSM ciphering key. 
Furthermore, the ME shall replace an already established UMTS 
security context for the PS domain, if any, in the USIM. The MS 
shall in addition handle the STARTps value as specified in 
3GPP TS 25.331 [23c]. 

At inter-system change from SI mode to A/Gb mode, if a GEA 
algorithm is taken into use that requires a 64-bit long ciphering 
key, then an ME shall apply the derived GPRS GSM ciphering 
key. 

At inter-system change from SI mode to A/Gb mode, if a GEA 
algorithm is taken into use that requires a 128-bit long ciphering 
key, then an ME shall apply the derived GPRS GSM Kci28 that 
was derived by the ME from the derived UMTS security keys 
(see subclause 4.7.7.3a). 



NOTE 2: For the case in table 4.7.7. 10.2, because of deriving a new UMTS security context for the PS domain, a 
new GPRS GSM ciphering key needs to be derived from the new derived UMTS security keys (i.e. CK' 
and IK'). The new GPRS GSM ciphering key is also part of the new UMTS security context for the PS 
domain, and therefore any old GPRS GSM ciphering key stored in the USIM and in the ME belongs to an 
old UMTS security context for the PS domain and can no longer be taken into use. 
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Table 4.7.7.1 0.3/3GPP TS 24.008: Inter-system change from SI mode to lu mode or A/Gb mode in idle 

mode when the TIN indicates "RAT-related TMSI" 



Security context established in MS and 
network 


At inter-system change to lu mode or A/Gb mode in idle mode 
when the TIN indicates "RAT-related TIVISI" 


UIVITS security context 


At inter-system change from S1 mode to lu mode, the ME shall 
apply the GPRS UMTS ciphering key and the GPRS UMTS 
integrity key that were received from the UMTS security context 
for the PS domain created in the USIM during the latest 
successful authentication procedure. 

At inter-system change from S1 mode to A/Gb mode, if a GEA 
algorithm is taken into use that requires a 64-bit long ciphering 
key, then an ME shall apply the GPRS GSM ciphering key that 
was received from the GSM security context created in the 
SIM/USIM during the latest successful authentication procedure. 
At inter-system change from S1 mode to A/Gb mode, if a GEA 
algorithm is taken into use that requires a 128-bit long ciphering 
key, then an ME shall apply the GPRS GSM Kci28 derived by the 
ME from the GPRS UMTS ciphering key and the GPRS UMTS 
integrity key (see 3GPP TS 33.102 [5a]) provided by the USIM 
during the lastest successful authentication procedure (see 
subclause 4.7.7.3a). 



The network shall replace an already established UMTS security context for the PS domain, if any, when a handover 
from SI mode to lu mode or from SI mode to A/Gb mode has been completed successfully. 

If the handover from SI mode to lu mode or SI mode to A/Gb mode has not been completed successfully, the ME and 
the network shall delete the new derived UMTS security context for the PS domain. Additionally, the network shall 
delete the already established UMTS security context for the PS domain, if the CKSN of the already established UMTS 
security context is equal to the CKSN of the new derived security context for the PS domain. 

4.7.8 Identification procedure 

The identification procedure is used by the network to request an MS to provide specific identification parameters to the 
network e.g. International Mobile Subscriber Identity, International Mobile Equipment Identity (see 
3GPP TS 23.003 [10]). For the presentation of the IMEI, the requirements of 3GPP TS 42.009 [5] apply. 



4.7.8.1 



Identification initiation by the network 



The network initiates the identification procedure by transferring an IDENTITY REQUEST message to the MS and 
starts the timer T3370. The IDENTITY REQUEST message specifies the requested identification parameters in the 
identity type information element. 

4.7.8.2 Identification response by the MS 

An MS that has been attached to GPRS shall be ready to respond to an IDENTITY REQUEST message at any time. 

Upon receipt of the IDENTITY REQUEST message the MS sends back an IDENTITY RESPONSE message. The 
IDENTITY RESPONSE message shall contain the identification parameters as requested by the network. 

4.7.8.3 Identification completion by the network 

Upon receipt of the IDENTITY RESPONSE the network shall stop timer T3370. 

4.7.8.3a Abnormal cases in the MS 

(a) Requested identity is not available: 

If the MS cannot encode the requested identity in the IDENTITY RESPONSE message, e.g. because no valid 
SIM is available, then it shall encode the identity type as "No identity". 
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4.7.8.4 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) Lower layer failure 

Upon detection of a lower layer failure before the IDENTITY RESPONSE is received, the network shall abort 
any ongoing GMM procedure. 

b) Expiry of timer T3370 

The identification procedure is supervised by the network by the timer T3370. The network shall, on the first 
expiry of the timer T3370, retransmit the IDENTITY REQUEST message and reset and restart the timer T3370. 
This retransmission is repeated four times, i.e. on the fifth expiry of timer T3370, the network shall abort the 
identification procedure and any ongoing GMM procedure. 

c) Collision of an identification procedure with a GPRS attach procedure 

If the network receives an ATTACH REQUEST message before the ongoing identification procedure has been 
completed and no GPRS attach procedure is pending on the network (i.e. no ATTACH ACCEPT/REJECT 
message has still to be sent as an answer to an ATTACH REQUEST message), the network shall proceed with 
the GPRS attach procedure. 

d) Collision of an identification procedure with a GPRS attach procedure when the identification procedure has 
been caused by a GPRS attach procedure 

If the network receives an ATTACH REQUEST message before the ongoing identification procedure has been 
completed and a GPRS attach procedure is pending (i.e. an ATTACH ACCEPT/REJECT message has to be sent 
as an answer to an earlier ATTACH REQUEST message), then: 

If one or more of the information elements in the ATTACH REQUEST message differs from the ones 
received within the previous ATTACH REQUEST message, the network shall proceed with the GPRS attach 
procedure; or 

If the information elements do not differ, then the network shall not treat any further this new ATTACH 
REQUEST. 

Collision of an identification procedure with an MS initiated GPRS detach procedure 

GPRS detach containing cause "power off: 

If the network receives a DETACH REQUEST message before the ongoing identification procedure has been 
completed, the network shall abort the identification procedure and shall progress the GPRS detach 
procedure. 

GPRS detach containing other causes than "power off": 

If the network receives a DETACH REQUEST message before the ongoing identification procedure has been 
completed, the network shall complete the identification procedure and shall respond to the GPRS detach 
procedure as described in subclause 4.7.4. 

e) Collision of an identification procedure with a routing area updating procedure 

If the network receives a ROUTING AREA UPDATE REQUEST message before the ongoing identification 
procedure has been completed, the network shall progress both procedures. 

f) Collision of an identification procedure with a service request procedure 

If the network receives a SERVICE REQUEST message before the ongoing identification procedure has been 
completed, the network shall progress both procedures. 
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Figure 4.7.8/1 3GPP TS 24.008: Identification procedure 



4.7.9 Paging procedure 



4.7.9.1 



Paging for GPRS services 



In A/Gb mode, paging is used by the network to identify the cell the MS has currently selected, or to prompt the mobile 
to re-attach if necessary as a result of network failure. If the MS is not GPRS attached when it receives a paging for 
GPRS services, the MS shall ignore the paging. 

In lu mode, paging is used by the network to request the establishment of PS signalling connection or to prompt the 
mobile to re-attach if necessary as a result of network failure. If the MS is not GPRS attached when it receives a paging 
for GPRS services, the MS shall ignore the paging. 



4.7.9.1.1 



Paging for GPRS services using P-TMSI 



The network shall initiate the paging procedure for GPRS services using P-TMSI when GMM signalling messages or 
user data is pending to be sent to the MS while the Mobile Reachable timer is running. The network may page only 
GPRS MSs which are GMM-REGISTERED and identified by a local P-TMSI. 

In lu mode, to initiate the procedure the GMM entity in the network requests the lower layer to start paging (see 
3GPP TS 25.331 [23c] and 3GPP TS 25.413 [19c]) and starts timer T3313. The GMM entity in the network may 
provide the lower layer with a list of CSG IDs, including the CSG IDs of both the expired and the unexpired 
subscriptions. If there is a PDN connection for emergency bearer services established, the GMM entity in the network 
shall not provide the list of CSG IDs to the lower layer. 

Upon reception of a paging indication, the MS shall stop the timer T3346, if running, and initiate a service request 
procedure to respond to the paging, the MS shall set the service type to "paging response" in the SERVICE REQUEST 
message (see 3GPP TS 24.007 [20], 3GPP TS 23.060 [74], 3GPP TS 25.331 [23c] and 3GPP TS 25.413 [19c]). If the 
paging request for GPRS services was received during an ongoing MS initiated GMM specific procedure, then the MS 
shall progress the GMM specific procedure, and the network shall proceed with the GMM specific procedure. 

In A/Gb mode, to initiate the procedure the GMM entity requests the RR sublayer to start paging (see 

3GPP TS 44.018 [84], 3GPP TS 44.060 [76]), and starts timer T3313. Upon reception of a paging indication, the MS 

shall respond to the paging with any LLC frame (see 3GPP TS 44.064 [78a], 3GPP TS 24.007 [20], 

3GPPTS 23.060 [74]). 

At intersystem change, an MS not having the READY timer running in A/Gb mode or an MS in PMM-IDLE mode in 
lu mode, being paged in a different access network as when it last sent user data or signalling message, uses ROUTING 
AREA UPDATE REQUEST message as paging response, i.e. the RA update procedure shall be performed instead 
according to the selective routing area update procedure. 

The network shall stop timer T3313 when a response is received from the MS. When the timer T3313 expires the 
network may reinitiate paging. 

In lu mode, when a response is received from the MS, the network shall change from PMM-IDLE mode to PMM- 
CONNECTED mode. 

In A/Gb mode, when a response different from an LLC NULL frame is received from the MS, the network shall start 
the READY timer. 
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4.7.9.1 .2 Paging for GPRS services using IMSI 

Paging for GPRS services using IMSI is an abnormal procedure used for error recovery in the network. 

The network may initiate paging using IMSI if the P-TMSI is not available due to a network failure. 

In lu mode, to initiate the procedure the GMM entity in the network requests the lower layer to start paging (see 
3GPP TS 25.331 [23c] and 3GPP TS 25.413 [19c]). 

In A/Gb mode, to initiate the procedure the GMM entity in the network requests the RR sublayer to start paging (see 
3GPP TS 44.018 [84], 3GPP TS 44.060 [76]). 

Upon reception of a paging indication for GPRS services using IMSI, the MS shall stop the timer T3346, if it is 
running, locally deactivate any active PDP context(s), MBMS context(s) and locally detach from GPRS. The local 
detach includes deleting any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number stored, setting 
the GPRS update status to GU2 NOT UPDATED and changing state to GMM-DEREGISTERED. The MS shall stop all 
timers T3396 that are running. 

If SI mode is supported by the MS, the MS shall in addition handle the EMM parameters EMM state, EPS update 
status, last visited registered TAI, TAJ list, GUTI and KSIasme as specified in 3GPP TS 24.301 [120] for the case when 
a paging for EPS services using IMSI is received. 

In lu mode, when an MS receives a paging request for GPRS services using the IMSI from the network before an MS 
initiated GMM specific procedure has been completed, then the MS shall abort the GMM specific procedure, and the 
MS shall proceed according to the description in this clause. 

After performing the local detach, the MS shall then perform a GPRS attach or combined GPRS attach procedure. 

After performing the attach, the MS should activate PDP context(s) to replace any previously active PDP context(s). 
The MS should also perform the procedures needed in order to activate any previously active multicast service(s). 

NOTE 1 ; In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS 
context(s) automatically. 

NOTE 2: The MS does not respond to the paging except with the Attach Request. Hence timer T3313 in the 
network is not used when paging with IMSI. 

NOTE 3: Paging without DRX parameters may require a considerable extension of the paging duration. 

4.7.9.2 Paging for non-GPRS services 

The network may initiate the paging procedure for non-GPRS services when the MS is IMSI attached for non-GPRS 

services. 

In lu mode, to initiate the procedure the GMM entity requests the lower layer to start paging (see 3GPP TS 25.331 [23c] 
and 3GPP TS 25.413 [19c]) for non-GPRS services. 

In A/Gb mode, to initiate the procedure the GMM entity requests the RR sublayer to start paging (see 
3GPP TS 44.018 [84] and 3GPP TS 44.060 [76] for non-GPRS services). 

The MS identity used for paging shall be the allocated TMSI if acknowledged by the MS, otherwise the IMSI. 

4.7.1 Receiving a GMM STATUS message by a GMM entity 

If the MS receives a GMM STATUS message no state transition and no specific action shall be taken as seen from the 
radio interface, i.e. local actions are possible. The actions to be taken on receiving a GMM STATUS message in the 
network are an implementation dependent option. 
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4.7.11 Void 

4.7.12 GMM Information procedure 

The GMM information message support is optional in the network. The MM information procedure may be invoked by 
the network at any time during an estabhshed GMM context. 

4.7.12.1 GMM information procedure initiation by the network 

The GMM information procedure consists only of the GMM INFORMATION message sent from the network to the 
mobile station. During an established GMM context, the network may send none, one, or more GMM INFORMATION 
messages to the mobile station. If more than one GMM INFORMATION message is sent, the messages need not have 
the same content. 

4.7.12.2 GMM information procedure in the mobile station 

When the mobile station (supporting the GMM information message) receives an GMM INFORMATION message, it 
shall accept the message and optionally use the contents to update appropriate information stored within the mobile 
station. 

If the mobile station does not support the GMM information message the mobile station shall ignore the contents of the 
message and return an GMM STATUS message with cause #97. 

4.7.13 Service Request procedure (lu mode only) 

The purpose of this procedure is to transfer the PMM mode from PMM-IDLE to PMM-CONNECTED mode, and/or to 
assign radio access bearer in case of PDF contexts are activated without radio access bearer assigned. In latter case, the 
PMM mode may be PMM-IDLE mode or may alternatively be the PMM-CONNECTED mode if the MS requires radio 
access bearer re-establishment. This procedure is used for; 

the initiation of CM layer service (e.g. SM or SMS) procedure from the MS in PMM-IDLE mode, 

the network to transfer down link signalling, 

- uplink (in PMM-IDLE or PMM CONNECTED) and downUnk (only in PMM-IDLE) user data, 

counting the number of mobile stations in a cell which are interested in a specific MBMS service. 

requesting the establishment of a point-to-point Radio Bearer for receiving a MBMS service. 

For downlink transfer of signalling or user data in PMM-IDLE mode, the trigger is given from the network by the 
paging request procedure, which is out of scope of the present document. 

For pending downlink user data in PMM-CONNECTED mode, the re -establishment of radio access bearers for all 
active PDP contexts is done without paging. 

For counting the number of mobile stations in PMM-IDLE mode interested in a specific MBMS service, the trigger is 
given from the network by the MBMS notification procedure (see 3GPP TS 25.331 [23c]). 

For establishing a point-to-point radio bearer to allow MBMS service, the trigger is given from the RRC determining 
this need from the MBMS control parameters broadcasted by the network (see 3GPP TS 25.331 [23c]). 

Service type can take either of the following values; "signalling", "data", "paging response", "MBMS multicast service 
reception" or "MBMS broadcast service reception". Each of the values shall be selected according to the criteria to 
initiate the Service request procedure. 

If the MS is triggered to send a Service Request message for both MBMS multicast service and MBMS broadcast 
service simultaneously, the MS shall include a Service Type indicating "MBMS multicast service reception". 

The criteria to invoke the Service request procedure are when; 
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a) the MS has any signalHng messages except GMM messages (e.g. for SM or SMS) to be sent to the network in 
PMM-IDLE mode (i.e., no secure PS signalHng connection has been estabhshed). In this case, the service type 
shall be set to "signalling". 

b) the MS, either in PMM-IDLE or PMM-CONNECTED mode, has pending user data to be sent, no radio access 
bearer is established for the corresponding PDP context, and timer T3319 (see subclause 4.7.13.3) is not running 
or, optionally, if timer T3319 is running and the flag in the Uplink data status IE for this PDP context has not 
been set in the last Service Request. The procedure is initiated by an indication from the lower layers (see 
3GPP TS 24.007 [20]). In this case, the service type shall be set to "data". 

c) the MS receives a paging request for PS domain from the network in PMM-IDLE mode. In this case, the service 
type shall be set to "paging response". 

d) the MS is in PMM-IDLE mode or PMM-CONNECTED, receives an MBMS notification for an MBMS 
multicast service for which the MS has activated an MBMS context or for an MBMS broadcast service which 
has been selected for reception locally by upper layers in the MS, and is prompted by the contents of the 
notification to establish a PS signalling connection (see 3GPP TS 25.346 [1 10]). In this case, the service type 
shall be set to "MBMS multicast service reception" or "MBMS broadcast service reception", respectively. 

e) the MS in PMM-IDLE mode or PMM-CONNECTED, determines from the broadcast MBMS control parameters 
that there is a need to establish a point-to-point Radio Bearer to enable MBMS reception (see 

3GPP TS 25.346 [1 10]). In this case, the service type shall be set to "MBMS multicast service reception" or 
"MBMS broadcast service reception", respectively. 

If one of the above criteria to invoke the Service request procedure is fulfilled, then the Service request procedure may 
only be initiated by the MS when the following conditions are fulfilled: 

its GPRS update status is GUI UPDATED and the stored RAJ is equal to the RAJ of the current serving cell; and 

no GMM specific procedure is ongoing (see subclause 4. 1 . 1 . 1). 

If a GMM specific procedure is ongoing at the time a request from CM sublayer, the RRC or the RABM (see 
3GPP TS 24.007 [20]) is received and the ATTACH REQUEST or ROUTING AREA UPDATE REQUEST message 
has been sent, then, depending on implementation, the MS shall abort the received request or delay it until the GMM 
specific procedure is completed. If the ATTACH REQUEST or ROUTING AREA UPDATE REQUEST message has 
not been sent, the MS may indicate "follow-on request pending" in the message (i.e. the MS wishes to prolong the 
established PS signalling connection after the GMM specific procedure). Then, the MS shall delay the Service request 
procedure until the GMM specific procedure is completed. 

If the network indicates "follow-on proceed" in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT 
message and the MS has a service request pending, the MS shall react depending on the service type. If the service type 
is: 

"signalling": the MS shall abort the Service request procedure and send the pending signalling messages 
immediately; 

"data": the MS shall immediately perform the pending Service request procedure using the current PS signalling 
connection; 

"paging response": the MS shall abort the Service request procedure. No further specific action is required from 
the MS. 

If the network indicates "follow-on proceed" and the MS has no service request pending, then no specific action is 
required from the MS. 

If the network indicates "no follow-on proceed" in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT 
message, the MS shall not initiate the pending Service request procedure until the current PS signalling connection is 
released. 

NOTE: The "follow-on proceed" indication was not defined in earlier versions of the protocol. A network that is 
compliant with the earlier versions of the protocol will always encode the respective bit as zero, i.e. as 
"follow-on proceed", even if it does not prolong the PS signalling connection. 

After completion of a Service request procedure but before re-establishment of radio access bearer, if the PDP and 
MBMS context status information elements are included, then the network shall deactivate all those PDP and MBMS 
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contexts locally (without peer to peer signalling between the MS and the network), which are not in SM state PDP- 
INACTIVE on network side but are indicated by the MS as being in state PDP-INACTIVE. 

After completion of a Service request procedure, the pending service is resumed and uses then the connection 
established by the procedure. If the service type is indicating "data", then the radio access bearers for all activated PDP 
contexts are re-established by the network, except for those activated PDP contexts having maximum bit rate value set 
to kbit/s for both uplink and downlink and as an option those which have no pending user data. The re -establishment 
of radio access bearers for those PDP contexts is specified in subclause 6.1.3.3. 

4.7.13.1 Service Request procedure initiation 

The MS initiates the Service request procedure by sending a SERVICE REQUEST message. The timer T3317 shall be 
started after the SERVICE REQUEST message has been sent and state GMM-SER VICE-REQUEST-INITIATED is 
entered. The message SERVICE REQUEST shall contain the P-TMSI and the Service type shall indicate either "data", 
"signalling", "paging response", "MBMS multicast service reception" or "MBMS broadcast service reception". The MS 
shall not issue another Service request when the MS is in state GMM-SER VICE-REQUEST-INITIATED 

If the PDP context status information element is included in the SERVICE REQUEST message, then the network shall 
deactivate all those PDP contexts locally (without peer to peer signalling between the MS and the network) which are 
not in SM state PDP-INACTIVE on the network side, but are indicated by the MS as being in state PDP-INACTIVE. 

If the MBMS context status information element is included in the SERVICE REQUEST message, then the network 
shall deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and network) which 
are not in SM state PDP-INACTIVE on the network side, but are indicated by the MS as being in state PDP- 
INACTIVE. If no MBMS context status information element is included, then the network shall deactivate all MBMS 
contexts locally which are not in SM state PDP-INACTIVE on the network side. 

For a Service Request of type "data", the MS may include the Uplink data status information element in the SERVICE 
REQUEST message. The Uplink data status information indicates which preserved PDP contexts have pending uplink 
data to be sent. If the Uplink data status information element is included in the SERVICE REQUEST message with 
service type "data", the network may use this information to determine which of the RABs for the preserved PDP 
contexts to re-establish. 

4.7.13.2 GMM common procedure initiation 

The network may initiate GMM common procedures, e.g. the GMM identification or the GMM authentication and 
ciphering procedure, depending on the received information such as GPRS ciphering key sequence number and P- 
TMSI. 

4.7.1 3.3 Service request procedure accepted by the network 

If the SERVICE REQUEST message was sent in PMM-IDLE mode, the indication from the lower layers that the 
security mode control procedure is completed shall be treated as a successful completion of the procedure. The timer 
T3317 shall be stopped, and the MS enters GMM-REGISTERED state and PMM-CONNECTED mode. 

If the SERVICE REQUEST message was sent in PMM-CONNECTED mode, then the reception of the SERVICE 
ACCEPT message shall be treated as a successful completion of the procedure. The timer T3317 shall be stopped and 
the MS remains in PMM-CONNECTED mode. 

Upon reception of the SERVICE REQUEST message, if the EMM Combined UE Waiting Flag is 'true', the SGSN shall 
complete the procedure and perform a detach procedure for non-GPRS services only as described in subclause 4.7.4.2. 

If the SERVICE REQUEST message was sent in a CSG cell and the CSG subscription has expired or was removed for 
a MS, but the MS has a PDN connection for emergency bearer services established, the network shall accept the 
SERVICE REQUEST message and deactivate all non-emergency PDP contexts by initiating PDP context deactivation 
procedure. The PDP contexts for emergency services shall not be deactivated. 

At successful completion of a service request procedure with Service type "data", the MS shall start timer T3319. The 
timer T3319 shall be stopped when the MS returns to PMM-IDLE mode or when the network releases the radio access 
bearer of any active PDP context. The MS shall not issue another Service Request with service type "data" while timer 
T3319 is running unless the Service request is being generated from a PDP context for which the flag in the Uplink data 
status IE has not been set in the last Service Request. 
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The network may indicate a value for timer T3319 in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT 
messages. The last provided value of T3319 shall be used by the MS. If the information element T3319 value is not 
included in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT messages, the default value shall be 
used. If the T3319 value received by the MS contains an indication that the timer is deactivated or the timer value is 
zero, then the MS shall use the default value. 

If the PDP context status information element is included in the Service Accept, then the MS shall deactivate locally 
(without peer to peer signalling between the MS and the network) all that PDP contexts which are not in SM state PDP- 
INACTIVE on MS side but are indicated by the Network as being in state PDP-INACTIVE. 

If the MBMS context status information element is included in the SERVICE ACCEPT message, then the MS shall 
deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and network) which are 
not in SM state PDP-INACTIVE in the MS, but are indicated by the network as being in state PDP-INACTIVE. If no 
MBMS context status information element is included, then the MS shall deactivate all those MBMS contexts locally 
which are not in SM state PDP-INACTIVE in the MS. 

If a service request is received from a MS with a LIPA PDN connection, and if: 

a L-GW Transport Layer Address is provided by the lower layer together with the service request, and the 
GGSN address associated with the PDP context of the LIPA PDN connection is different from the provided L- 
GW Transport Layer Address (see 3GPP TS 25.413 [19c]); or 

no L-GW Transport Layer Address is provided together with the service request by the lower layer, 

then the SGSN explicitly deactivates all PDP contexts associated with the LIPA PDN connection by initiating the PDP 
context deactivation procedure. 

4.7.1 3.4 Service request procedure not accepted by the network 

If the Service request cannot be accepted, the network returns a SERVICE REJECT message to the mobile station. 

If the service request for mobile originated services is rejected due to general NAS level mobility management 
congestion control, the network shall set the GMM cause value to #22 "congestion" and assign a back-off timer T3346. 

An MS that receives a SERVICE REJECT message stops timer T3317. The MS shall then take different actions 
depending on the received reject cause value; 

# 3 (Illegal MS); or 

# 6 (Illegal ME); 

- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and enter the state GMM-DEREGISTERED. Furthermore, it shall delete any P-TMSI, P- 
TMSI signature, RAJ and GPRS ciphering key sequence number and shall consider the SIM/USIM as invalid for 
GPRS services until switching off or the SIM/USIM is removed. 

- A GPRS MS operating in MS operation mode A shall in addition set the update status to U3 ROAMING NOT 
ALLOWED, shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS 
operation mode A and an RR connection exists, the MS shall abort the RR connection, unless an emergency call 
is ongoing. The SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the 
SIM/USIM is removed. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
service request procedure is rejected with the EMM cause with the same value. 

# 7 (GPRS services not allowed); 

- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2.9) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence 
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM 
is removed. The new state is GMM-DEREGISTERED. 
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A GPRS MS operating in MS operation mode A or B in network operation mode I which is already IMSI 
attached for CS services is still IMSI attached for CS services in the network, and shall set the timer T3212 to its 
initial value and restart it, if it is not already running. 

A GPRS MS operating in MS operation mode A or B in network operation mode I shall proceed with the 
appropriate MM specific procedure according to the MM service state. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
service request procedure is rejected with the EMM cause with the same value. 

# 9 (MS identity cannot be derived by the network); 

- The MS shall set the GPRS update status to GU2 NOT UPDATED (and shall store it according to 
subclause 4.1.3.2), enter the state GMM-DEREGISTERED, and shall delete any P-TMSI, P-TMSI signature, 
RAI and GPRS ciphering key sequence number. If the rejected request was not for initiating a PDN connection 
for emergency bearer services, the MS may subsequently, automatically initiate the GPRS attach procedure. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
service request procedure is rejected with the EMM cause with the same value. 

# 10 (Implicitly detached); 

- The MS shall change to state GMM-DEREGISTERED.NORMAL-SERVICE. If the rejected request was not for 
initiating a PDN connection for emergency bearer services, the MS shall then perform a new attach procedure. 
The MS should also activate PDP context(s) to replace any previously active PDP contexts. The MS should also 
perform the procedures needed in order to activate any previously active multicast service(s). 

If SI mode is supported in the MS, the MS shall handle the EMM state as specified in 3GPP TS 24.301 [120] for 
the case when the the service request procedure is rejected with the EMM cause with the same value. 

NOTE 1 : In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS 
context(s) automatically. 

# 1 1 (PLMN not allowed); 

The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2) 
and enter the state GMM-DEREGISTERED. 

- The MS shall store the PLMN identity in the "forbidden PLMN hst". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- A GPRS MS operating in MS operation mode A shall set the update status to U3 ROAMING NOT 
ALLOWED and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM 
IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23. 122 [14]. 

An MS in GAN mode shall request a PLMN Hst in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this Hst according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI hst and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
service request procedure is rejected with the EMM cause with the same value. 

# 12 (Location area not allowed); 
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The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set 
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2) 
and shall change to state GMM-DEREGISTERED.LIMITED-SERVICE. 

The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall 
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt 
counter. The new MM state is MM IDLE. 

- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. 

NOTE 2; The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status, 
GUTI, last visited registered TAI, TAI Ust and KSI as specified in 3GPP TS 24.301 [120] for the case when the 
service request procedure is rejected with the EMM cause with the same value. 

#13 (Roaming not allowed in this location area); 

- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall change to state GMM-REGISTERED.LIMITED-SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
reset the location update attempt counter. The new MM state is MM IDLE. 

- The MS shall perform a PLMN selection according to 3GPP TS 23.122 [14]. 

An MS in GAN mode shall request a PLMN Ust in GAN (see 3GPP TS 44.318 [76b]) prior to perform a 
PLMN selection from this list according to 3GPP TS 23.122 [14]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status 
as specified in 3GPP TS 24.301 [120] for the case when the service request procedure is rejected with the EMM 
cause with the same value. 

# 15 (No Suitable Cells In Location Area); 

- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall change to state GMM-REGISTERED.LIMITED-SERVICE. 

The MS shall store the LAI in the list of "forbidden location areas for roaming". 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is 
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the 
RR connection is subsequently released: 

- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall 
reset the location update attempt counter. The new MM state is MM IDLE. 

The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN 
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121]. 
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NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status 
as specified in 3GPP TS 24.301 [120] for the case when the service request procedure is rejected with the EMM 
cause with the same value. 

#22 (Congestion); 

If the T3346 value IE is present in the SERVICE REJECT message and the value indicates that this timer is 
neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be considered as an 
abnormal case and the behaviour of the MS for this case is specified in subclause 4.7. 13.5. 

If the rejected request was not for initiating a PDN connection for emergency bearer services, the MS shall abort 
the service request procedure and enter state GMM -REGISTERED, and stop timer T3317 if still running. 

The MS shall stop timer T3346 if it is running. 

If the SERVICE REJECT message is integrity protected, the MS shall start timer T3346 with the value provided 
in the T3346 value IE. 

If the SERVICE REJECT message is not integrity protected, the MS shall start timer T3346 with a random value 
from the default range specified in table 11. 3a. 

The MS stays in the current serving cell and applies normal cell reselection process. The service request 
procedure may be started by CM layer, if it is still necessary, when timer T3346 expires or is stopped. 

A GPRS MS operating in MS operation mode A or B which is already IMSI attached for CS services in the 
network is still IMSI attached for CS services in the network. 

# 25 (Not authorized for this CSG) 

Cause #25 is only applicable in UTRAN lu mode and when received from a CSG cell. Other cases are 
considered as abnormal cases and the specification of the mobile station behaviour is given in 
subclause 4.7.13.5. 

If the SERVICE REJECT message with cause #25 was received without integrity protection, then the MS shall 
discard the message. 

- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to 
subclause 4.1.3.2) and shall change to state GMM-REGISTERED.LIMITED-SERVICE. 

- If the CSG ID and associated PLMN identity of the cell where the MS has sent the SERVICE REQUEST 
message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry corresponding to 
this CSG ID and associated PLMN identity from the Allowed CSG list. 

- If the CSG ID and associated PLMN identity of the cell where the MS has sent the SERVICE REQUEST 
message are contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14] 
subclause 3.1 A. 

The MS shall start timer T3340 as described in subclause 4.7.1.9. 

- The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and 
3GPPTS 25.304 [98]. 

If SI mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status 
as specified in 3GPP TS 24.301 [120] for the case when the service request procedure is rejected with the EMM 
cause with the same value. 

# 40 (No PDP context activated) 

- The MS shall deactivate locally all active PDP and MBMS contexts and the MS shall enter the state GMM- 
REGISTERED.NORMAL-SERVICE. The MS may also activate PDP context(s) to replace any previously 
active PDP contexts. The MS may also perform the procedures needed in order to activate any previously active 
multicast service(s). 
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NOTE 4: In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS 
context(s) automatically. 

Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is described in 
subclause 4.7.13.5. 

4.7.1 3.4a Service request procedure for initiating a PDN connection for emergency bearer 

services not accepted by the network 

If the service request for initiating a PDN connection for emergency bearer services cannot be accepted by the network, 
the MS shall perform the procedures as described in subclause 4.7.13.4. Then if the MS is in the same selected PLMN 
where the last service request was attempted, the MS shall: 

a) inform the upper layers. This could result in the MS attempting a CS emergency call (if not already attempted in 
the CS domain) or other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [95] 
that can result in the emergency call being attempted to another IP-CAN; or 

b) detach locally, if not detached already, attempt GPRS attach for emergency bearer services. 

4.7.1 3.5 Abnormal cases in the MS 

The following abnormal cases can be identified: 

a) Access barred because of access class control 

The Service request procedure shall not be started. The MS stays in the current serving cell and applies normal 
cell reselection process. The Service request procedure may be started by CM layer if it is still necessary, i.e. 
when access is granted or because of a cell change. 

b) Lower layer failure without "Extended wait time" received from lower layers before the security mode control 
procedure is completed, SERVICE ACCEPT or SERVICE REJECT message is received. 

The procedure shall be aborted except in the following implementation option cases b.l, b.2 and b.3. 

b. 1) Release of PS signalling connection in lu mode (i.e. RRC connection release) before the completion of the 
service request procedure 

The service request procedure shall be initiated again, if the following conditions apply: 

i) The original service request procedure was initiated over an existing PS signalling connection; and 

ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to 
the PS signalling connection were received after the SERVICE REQUEST message was transmitted. 

b.2) RR release in lu mode (i.e. RRC connection release) with cause different than "Directed signalling 
connection re-establishment", for example, "Normal", or "User inactivity" (see 3GPP TS 25.331 [32c] and 
3GPPTS 44.118 [111]) 

The service request procedure shall be initiated again, if the following conditions apply: 

i) The original service request procedure was initiated over an existing RRC connection and, 

ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to 
the PS signalling connection were received after the SERVICE REQUEST messge was transmitted. 

NOTE: The RRC connection release cause different than "Directed signalling connection re-establishment" that 
triggers the re-initiation of the service request procedure is implementation specific. 

b.3) RR release in lu mode (i.e. RRC connection release) with cause "Directed signalling connection re- 
establishment" (see 3GPPTS 25.331 [32c] and 3GPPTS 44.118 [111]) 

The routing area updating procedure shall be initiated followed by a rerun of the service request procedure if the 
following condition applies: 
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i) The service request procedure was not due to a rerun of the procedure due to "Directed signalling 
connection re-establishment". 

c) T33 17 expired 

The MS shall enter GMM-REGISTERED state. 

If the MS is in PMM-IDLE mode then the procedure shall be aborted and the MS shall release locally any 
resources allocated for the service request procedure. 

If the MS is in PMM-CONNECTED mode, then the procedure shall be aborted. 

d) SERVICE REJECT received, other causes than those treated in subclause 4.7.13.4, and cases of GMM cause 
#22, if considered as abnormal cases according to subclause 4.7.13.4 

The procedure shall be aborted. 

e) Routing area update procedure is triggered 

If a cell change into a new routing area occurs and the necessity of routing area update procedure is determined 
before the security mode control procedure is completed, a SERVICE ACCEPT or SERVICE REJECT message 
has been received, the Service request procedure shall be aborted and the routing area updating procedure is 
started immediately. Follow-on request pending may be indicated in the ROUTING AREA UPDATE 
REQUEST for the service, which was the trigger of the aborted Service request procedure, to restart the pending 
service itself or the Service request procedure after the completion of the routing area updating procedure. If the 
Service type of the aborted SERVICE REQUEST was indicating "data", then the routing area update procedure 
may be followed by a re-initiated Service request procedure indicating "data", if it is still necessary. If the 
Service type was indicating "MBMS multicast service reception", or "MBMS broadcast service reception" the 
Service request procedure shall be aborted. 

f) Power off 

If the MS is in state GMM-SER VICE-REQUEST-INITIATED at power off, the GPRS detach procedure shall be 
performed. 

g) Procedure collision 

GPRS detach containing detach type "re-attach required" or "re-attach not required": 

If the MS receives a DETACH REQUEST message from the network in state GMM-SER VICE-REQUEST- 
INITIATED, the GPRS detach procedure shall be progressed and the Service request procedure shall be aborted. 
If the cause IE, in the DETACH REQUEST message, indicated a "re-attach required", the GPRS attach 
procedure shall be performed. If the GPRS Detach Request message contains detach type "re-attach not 
required" and GMM cause #2 "IMSI unknown in HLR", the MS will follow the procedure as described below 
for the detach type "IMSI detach". 

GPRS detach containing detach type "IMSI detach": 

If the MS receives a DETACH REQUEST message from the network in state GMM-SER VICE-REQUEST- 
INITIATED, the network and the MS shall progress both procedures. 

h) "Extended wait time" for PS domain from the lower layers 

The MS shall abort the service request procedure, enter state GMM-REGISTERED, and stop timer T3317 if still 
running. 

If the SERVICE REQUEST message contained the NAS signalling low priority indication set to "MS is 
configured for NAS signalling low priority", the MS shall start timer T3346 with the "Extended wait time" 
value. 

In other cases the MS shall ignore the "Extended wait time". 

The service request procedure is started, if still necessary, when timer T3346 expires or is stopped. 

m) Timer T3346 is running 
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The MS shall not start the service request procedure unless the MS has a PDN connection for emergency bearer 
services established or is establishing a PDN connection for emergency bearer services. The MS stays in the 
current serving cell and applies normal cell reselection process. The service request procedure is started, if still 
necessary, when timer T3346 expires or is stopped. 

4.7.1 3.6 Abnormal cases on the network side 

The following abnormal cases can be identified: 

a) Lower layer failure 

If a low layer failure occurs before the security mode control procedure is completed, a SERVICE ACCEPT or 
SERVICE REJECT message has been sent to the MS, the network enters/stays in PMM-IDLE. 

b) Protocol error 

If the SERVICE REQUEST message is received with a protocol error, the network shall return a SERVICE 
REJECT message with one of the following reject causes: 

#96: Mandatory information element error; 

#99: Information element non-existent or not implemented; 

#100: Conditional IE error; 

#111: Protocol error, unspecified. 

The network stays in PMM-IDLE mode. 

c) More than one SERVICE REQUEST received and the procedure has not been completed (i.e., the security mode 
control procedure has not been completed or SERVICE ACCEPT, SERVICE REJECT message has not been 
sent) 

If one or more of the information elements in the SERVICE REQUEST message differs from the ones 
received within the previous SERVICE REQUEST message, the previously initiated Service request 
procedure shall be aborted and the new Service request procedure shall be progressed; 

If the information elements do not differ, then the network shall continue with the previous Service request 
procedure and shall not treat any further this SERVICE REQUEST message. 

d) ATTACH REQUEST received before the security mode control procedure has been completed or an SERVICE 
ACCEPT or an SERVICE REJECT message has been sent 

If an ATTACH REQUEST message is received and the security mode control procedure has not been completed 
or an SERVICE ACCEPT or an SERVICE REJECT message has not been sent, the network may initiate the 
GMM common procedures, e.g. the GMM authentication and ciphering procedure. The network may e.g. after a 
succesful GMM authentication and ciphering procedure execution, abort the Service request procedure, the 
GMM context, PDP contexts and MBMS contexts, if any, are deleted and the new ATTACH REQUEST is 
progressed. 

e) ROUTING AREA UPDATE REQUEST message received before the security mode control procedure has been 
completed or an SERVICE ACCEPT or an SERVICE REJECT message has been sent 

If an ROUTING AREA UPDATE REQUEST message is received and the security mode control procedure has 
not been completed or an SERVICE ACCEPT or an SERVICE REJECT message has not been sent, the network 
may initiate the GMM common procedures, e.g. the GMM authentication and ciphering procedure. The network 
may e.g. after a successful GMM authentication and ciphering procedure execution, abort the Service request 
procedure and progress the routing area update procedure. 

f) If the Service Type indicates 'data' and the network fails to re-establish some or all RAB(s) then the SGSN may 
determine if PDP Context Modification or PDP Context Deactivation should be initiated. 

The appropriate action is an operator choice and depends on the QoS profile of the PDP Context, and the Uplink 
data status. 
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4.7.14 Void 

5 Elementary procedures for circuit-switched Call 

Control 

5.1 Overview 
5.1.1 General 

This subclause describes the call control (CC) protocol, which is one of the protocols of the Connection Management 
(CM) sublayer (see 3GPP TS 24.007 [20]). 

Every mobile station must support the call control protocol. If a mobile station does not support any bearer capability at 
all then it shall respond to a SETUP message with a RELEASE COMPLETE message as specified in subclause 5.2.2.2. 

In lu mode only, integrity protected signalling (see subclause 4.1.1.1.1 of the present document and in general, see 
3GPP TS 33.102 [5a]) is mandatory. In lu mode only, all protocols shall use integrity protected signalling. Integrity 
protection of all CC signalling messages is the responsibility of lower layers. It is the network which activates integrity 
protection. This is done using the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.1 18 [111]). 

In the call control protocol, more than one CC entity are defined. Each CC entity is independent from each other and 
shall communicate with the correspondent peer entity using its own MM connection. Different CC entities use different 
transaction identifiers. 

With a few exceptions the present document describes the call control protocol only with regard to two peer entities. 
The call control entities are described as communicating finite state machines which exchange messages across the 
radio interface and communicate internally with other protocol (sub)layers. This description is only normative as far as 
the consequential externally observable behaviour is concerned. 

Certain sequences of actions of the two peer entities compose "elementary procedures" which are used as a basis for the 
description in this subclause. These elementary procedures may be grouped into the following classes: 

call establishment procedures; 

call clearing procedures; 

- call information phase procedures; 

- miscellaneous procedures. 

The terms "mobile originating" or "mobile originated" (MO) are used to describe a call initiated by the mobile station. 
The terms "mobile terminating" or "mobile terminated" (MT) are used to describe a call initiated by the network. 

Figure 5.1a/3GPP TS 24.008 gives an overview of the main states and transitions on the mobile station side. 

The MS side extension figure 5.1a.l/3GPP TS 24.008 shows how for the Network Initiated MO call the MS reaches 
state Ul.O from state UO $(CCBS)$. 

Figure 5.1a.2/3GPP TS 24.008 illustrates the additional state transitions possible in the MS due to SRVCC handovers 
from PS to CS. 

Figure 5.1b/3GPP TS 24.008 gives an overview of the main states and transitions on the network side. 

The Network side extension figure 5.1b. 1/3GPP TS 24.008 shows for Network Initiated MO Calls the Network reaches 
state Nl.O from state NO $(CCBS)$. 

Figure 5.1b.2/3GPP TS 24.008 illustrates the additional state transitions possible in the network due to SRVCC 
handovers from PS to CS. 



£75/ 



3GPP T5 24.008 version 10.10.0 Release 10 



213 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



MNCC-SETUP.REQ. 



MMCC. EST. IND (SETUP) 



MNCC-CALL.CONF.REQ. 




O 
MMCC.SYNC.IND. 
(res. ass.) 



MNCC-SYNC-IND 
(res. ass) 



Dl (PROGRESS) 



f) early assignment 

NOTE: 

DR(MESSAGE) = MMCC_DATA_REQ(MESSAGE) 

Dl (MESSAGE) = MMCC_DATA IND (MESSAGE) 



Figure 5.1a/3GPP TS 24.008: Overview call control protocol/MS side 
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Figure 5.1a.1/3GPP TS 24.008: Overview call control protocol/MS side, extension 
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Figure 5.1a.2/3GPP TS 24.008: Overview call control protocol/MS side, extension for SRVCC from PS 

toCS 
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Figure 5.1b/3GPP TS 24.008 Overview call control protocol/Network side 
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Figure 5.1b.1/3GPP TS 24.008 Overview call control protocol/Network side, extension 
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Figure 5.1b.2/3GPP TS 24.008: Overview call control protocol/MS side, extension for SRVCC from PS 
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5.1.2 Call Control States 

5.1 .2.1 Call states at the mobile station side of the interface 

The states which may exist on the mobile station side of the radio interface are defined in this subclause. 

NOTE: States UO.l, U0.2, U0.3, U0.4, U0.5, U0.6, U26, and U27 are 3GPP specific. All other states are ITU-T 
defined. 

5.1.2.1.1 Null (State UO) 

No call exists. 

5.1 .2.1 .2 MM Connection pending (UO.l ) 

This state exists for a mobile originating call, when the mobile station requests the establishment of a MM connection. 

5.1 .2.1 .2a CC prompt present (U0.2) $(CCBS)$ 

This state exists for a mobile originating call when the network has prompted the mobile station to establish a CC 
connection but the mobile station has not yet responded. 

NOTE: This state is transient. 

5.1 .2.1 .2b Wait for network information (U0.3) $(CCBS)$ 

This state exists for a mobile originating call when the mobile station has responded to the prompt from the network to 
establish a CC connection and the mobile station is waiting for further information from the network. 

5.1 .2.1 .2c CC-Establishment present (U0.4) $(CCBS)$ 

This state exists for a mobile originating call when the mobile station has received a CC-establishment request but has 
not yet responded. 

NOTE: This state is transient. 

5.1 .2.1 .2d CC-Establishment confirmed (U0.5) $(CCBS)$ 

This state exists for a mobile originating call when the mobile station has sent the acknowledgement that the mobile 
station has received all the CC information that is needed. 

5.1 .2.1 .2e Recall present (U0.6) $(CCBS)$ 

This state exists for a mobile originating call when the mobile station has received a recall request but has not yet 
responded. 

NOTE: This state is transient. 

5.1.2.1.3 Call initiated (U1) 

This state exists for a mobile originating call, when the MS requests call establishment from the network. 

5.1 .2.1 .4 Mobile originating call proceeding (US) 

This state exists for a mobile originating call when the mobile station has received acknowledgement that the network 
has received all call information necessary to effect call establishment. 
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5.1.2.1.5 Call delivered (U4) 

This state exists for a mobile originating call, when the calling mobile station has received an indication that remote 
user alerting has been initiated. 

5.1.2.1.6 Call present (U6) 

This state exists for a mobile terminating call when the mobile station has received a call establishment request but has 
not yet responded. 

5.1.2.1.7 Call received (U7) 

This state exists for a mobile terminating call when the mobile station has indicated alerting but has not yet answered. 

5.1.2.1.8 Connect Request (U8) 

This state exists for a mobile terminating call, when the mobile station has answered the call and is waiting to be 
awarded the call. 

5.1 .2.1 .9 Mobile terminating call confirmed (U9) 

This state exists for a mobile terminating call when the mobile station has sent acknowledgement that the mobile station 
has received all call information necessary to effect call establishment. 

5.1.2.1.10 Active (U10) 

This state exists for a mobile terminating call when the MS has answered the call. This state exists for a mobile 
originating call when the MS has received an indication that the remote user has answered the call.. 

5.1.2.1.11 Disconnect request (U11) 

This state exists when the mobile station has requested the network to clear the end-to-end connection (if any) and is 
waiting for a response. 

5.1.2.1.12 Disconnect indication (U12) 

This state exists when the mobile station has received an invitation to disconnect because the network has disconnected 
the end-to-end connection (if any). 

5.1.2.1.13 Release request (U 19) 

This state exists when the MS has requested the network to release and is waiting for a response. 

5.1.2.1.14 Mobile originating modify (U26) 

This state exists when the mobile station has sent a request to the network for a new mode but has not yet received an 
answer. 

5.1.2.1.15 Mobile terminating modify (U27) 

This state exists when the mobile station has received a request from the network for a new mode and has not yet sent a 
response to this request. 

5.1.2.2 Network call states 

NOTE: States NO.l, N0.2, N0.3, N0.4, N0.5, N0.6, N26, N27, N28, N3a, N4,a, N7a, and N9a are 3GPP specific. 
All other states are ITU-T defined. 

The call states that may exist on the network side of the radio interface are defined in this subclause. 
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5.1.2.2.1 Null (State NO) 

No call exists. 

5.1 .2.2.2 MM connection pending (N0.1 ) 

This state exists for a mobile terminating call, when the network requests the establishment of a MM connection. 

5.1 .2.2.2a CC connection pending (N0.2) $(CCBS)$ 

This state exists for a mobile originating call when the network has requested the mobile station to estabhsh a CC 
connection. 

5.1 .2.2.2b Network answer pending (NO. 3) $(CCBS)$ 

This state exists for a mobile originating call when the mobile station has established a CC connection upon the request 
of the network, but the network has not yet informed the mobile station of the reason for the network's action. 

5.1 .2.2.2c CC-Establishment present (N0.4) $(CCBS)$ 

This state exists for a mobile originating call when the network has sent a CC establishment request but has not yet 
received a satisfactory response. 

5.1 .2.2.2d CC-Establishment confirmed (N0.5) $(CCBS)$ 

This state exists for a mobile originating call when the network has received acknowledgement that the mobile station 
has received all call information necessary to effect call establishment.5.1.2.2.2e Recall present (N0.6) $(CCBS)$ 

This state exists for a mobile originating call when the network has sent a recall request but has not yet received a 
satisfactory response. 

5.1.2.2.3 Call initiated (N1) 

This state exists for a mobile originating call when the network has received a call establishment request but has not yet 
responded. 

5.1 .2.2.4 Mobile originating call proceeding (N3) 

This state exists for a mobile originating call when the network has sent acknowledgement that the network has 
received all call information necessary to effect call establishment. 

5.1.2.2.5 Call delivered (N4) 

This state exists for a mobile originating call when the network has indicated that remote user alerting has been 
initiated. 

5.1.2.2.6 Call present (N6) 

This state exists for a mobile terminating call when the network has sent a call establishment request but has not yet 
received a satisfactory response. 

5.1.2.2.7 Call received (N7) 

This state exists for a mobile terminating call when the network has received an indication that the mobile station is 
alerting but has not yet received an answer. 

5.1 .2.2.8 Connect request (N8) 

This state exists for a mobile terminating call when the network has received an answer but the network has not yet 
awarded the call. 
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5.1 .2.2.9 Mobile terminating call confirmed (N9) 

This state exists for a mobile terminating call when the network has received acknowledgement that the mobile station 
has received all call information necessary to effect call establishment. 

5.1.2.2.10 Active (N10) 

This state exists for a mobile terminating call when the network has awarded the call to the called mobile station. This 
state exists for a mobile originating call when the network has indicated that the remote user has answered the call. 

5.1.2.2.11 Not used 

5.1.2.2.12 Disconnect indication (N12) 

This state exists when the network has disconnected the end- to-end connection (if any) and has sent an invitation to 
disconnect the mobile station to network connection. 

5.1.2.2.13 Release request (N 19) 

This state exists when the network has requested the MS to release and is waiting for a response. 

5.1 .2.2.14 Mobile originating modify (N26) 

This state exists when the network has received a request from the mobile station for a new mode but has not yet sent a 
response. 

5.1.2.2.15 Mobile terminating modify (N27) 

This state exists when the network has sent a request to the mobile station for a new mode but has not yet received an 
answer. 

5.1.2.2.16 Connect Indication (N28) 

This state exists for a mobile originating call when the network has indicated that the remote user has answered the call 
and the network is waiting for acknowledgement by the mobile station. 

5.2 Call establishment procedures 

Establishment of a call is initiated by request of upper layer in either the mobile station or the network; it consists of: 

the establishment of a CC connection between the mobile station and the network; 

the activation of the codec or interworking function. 

Whenever it is specified in the present document clause 5 that the mobile station shall attach the user connection, this 
means that the mobile station shall activate the codec or interworking function as soon as an appropriate channel is 
available. The mobile station shall de-activate the codec or interworking function whenever an appropriate channel is no 
longer available. As soon as an appropriate channel is (again) available, the codec or interworking function shall be re- 
activated. If a new order to attach the user connection is received, the new order shall supersede the previous one. 

A channel shall be considered as appropriate if it is consistent with the possibly negotiated bearer capability applicable 
for the actual phase of the call. The mobile station shall not consider a channel as not appropriate because the type of 
the channel (full rate/half rate) is not the preferred one. If: 

the user connection has to be attached but no appropriate channel is available for a contiguous time of 30 
seconds; or if 

the codec or interworking function is de-activated for a contiguous time of 30 seconds; 

then the mobile station may initiate call clearing. 
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Upon request of upper layers to establish a call, restricting conditions for the establishment of the call are examined. 
These restricting conditions concern the states of parallel CC entities and are defined elsewhere. If these restricting 
conditions are fulfilled, the call establishment is rejected. Otherwise a CC entity in state UO, "null", is selected to 
establish the call. It initiates the establishment by requesting the MM sublayer to establish an MM connection. 

In lu mode, if the lower layers indicate the release of a radio access bearer, whereas the corresponding call is still active, 
the MS shall not automatically initiate the release of that call. 

5.2.1 Mobile originating call establishment 

The call control entity of the mobile station initiates establishment of a CC connection by requesting the MM sublayer 
to establish a mobile originating MM connection and entering the "MM connection pending" state. There are two kinds 
of a mobile originating call: basic call and emergency call. The request to establish an MM connection shall contain a 
parameter to specify whether the call is a basic or an emergency call. This information may lead to specific qualities of 
services to be provided by the MM sublayers. Timer T303 is started when the CM SERVICE REQUEST message is 
sent. 

For mobile stations supporting eMLPP basic calls may optionally have an associated priority level as defined in 
3GPP TS 23.067 [88]. This information may also lead to specified qualities of service to be provided by the MM 
sublayers. 

While being in the "MM connection pending" state, the call entity of the mobile station may cancel the call prior to 
sending the first call control message according to the rules given in subclause 4.5.1.7. 

The mobile station supporting multicall that is initiating an emergency call shall release one or more existing call to 
ensure the emergency call can be established if the multicall supported information stored in the mobile station 
described in subclauses 5.2.1.2 and 5.2.2.1 indicates the network does not support multicall and some ongoing calls 

exists. 

Having entered the "MM connection pending" state, upon MM connection establishment, the call control entity of the 
mobile station sends a setup message to its peer entity. This setup message is 

a SETUP message, if the call to be established is a basic call, and 

an EMERGENCY SETUP message, if the call to be established is an emergency call. 

The mobile station then enters the "call initiated" state. Timer T303 is not stopped. 

The setup message shall contain all the information required by the network to process the call. In particular, the 
SETUP message shall contain the called party address information. 

If the mobile station supports multicall, it shall include the Stream Identifier (SI) information element. For the first call 
i.e. when there are no other ongoing calls the SI value shall be 1. 

For speech calls the mobile station shall indicate all codecs that it supports for UTRAN in the Supported Codec List 
information element. Codecs for GERAN shall be indicated in the Bearer Capability information element, if this 
information element is included. Additionally, if the mobile station supports codecs for GERAN and UTRAN, it shall 
indicate the codecs for GERAN also in the Supported Codec List information element. 

If the call is a redial attempt to switch from speech to multimedia or vice-versa, the SETUP message shall include the 
Redial information element. 

NOTE: Redial attempt is defined in 3GPP TR 23.903: "Redial solution for voice-video switching" [1 15]. 

If the MS supports the enhanced network-initiated in-call modification procedure as specified in subclause 5.3.4.3, the 
MS shall indicate this in the Call Control Capabilities IE in the SETUP message. 

If timer T303 elapses in the "MM connection pending" state, the MM connection in progress shall be aborted and the 
user shall be informed about the rejection of the call. 
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5.2.1.1 Call initiation 

The "call initiated" state is supervised by timer T303.For normal MO calls, this timer will have already been started 
after entering the "MM connection pending" state. For network-initiated MO calls this timer will be started in the recall 
present state as defined in subclause 5.2.3.4 

When the call control entity of the mobile station is in the "call initiated" state and if it receives: 

i) a CALL PROCEEDING message, it shall proceed as described in subclause 5.2.1.3; 

ii) an ALERTING message, it shall proceed as described in subclause 5.2.1.5; 

iii) a CONNECT message, it shall proceed as described in subclause 5.2.1.6; 

iv) a RELEASE COMPLETE message it shall proceed as described in subclause 5.2.1.2. 

Abnormal case: 

- If timer T303 elapses in the "call initiated" state before any of the CALL PROCEEDING, ALERTING, 
CONNECT or RELEASE COMPLETE messages has been received, the clearing procedure described in 
subclause 5.4 is performed. 

5.2.1.2 Receipt of a setup message 

In the "null" or "recall present" states, upon receipt of a setup message (a SETUP message or an EMERGENCY SETUP 
message, see subclause 5.2.1.1), the call control entity of the network enters the "call initiated" state. It shall then 
analyse the call information contained in the setup message. 

In lu mode, network shall include the SI received in the SETUP message into the RABid and send it back to the mobile 
station. For RABid see 3GPP TS 25.413 [19c] and 3GPP TS 44.1 18 [1 1 1]. If the network receives the SETUP message 
with no SI, the network shall set the SI value to 1 . 

i) If, following the receipt of the setup message, the call control entity of the network determines that the call 
information received from the mobile station is invalid (e.g. invalid number), then the network shall initiate call 
clearing as defined in subclause 5.4 with one of the following cause values: 

# 1 "unassigned (unallocated) number", 
#3 "no route to destination", 

# 22 "number changed", 

# 28 "invalid number format (incomplete number)". 

ii) If, following the receipt of the setup message, the call control entity of the network determines that a requested 
service is not authorized or is not available, it shall initiate call clearing in accordance with subclause 5.4.2 with 
one of the following cause values: 

# 8 "operator determined barring", 

# 57 "bearer capability not authorized", 

# 58 "bearer capability not presently available", 

# 63 "service or option not available, unspecified", or 

# 65 "bearer service not implemented". 

iii) Otherwise, the call control entity of the network shall either: 

send a CALL PROCEEDING message to its peer entity to indicate that the call is being processed; and enter 
the "mobile originating call proceeding" state; 

or: send an ALERTING message to its peer entity to indicate that alerting has been started at the called user 
side; and enter the "call received" state; 
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or: send a CONNECT message to its peer entity to indicate that the call has been accepted at the called user 
side; and enter the "connect request" state. 

The call control entity of the network may insert bearer capability information element(s) in the CALL 
PROCEEDING message to select options presented by the mobile station in the Bearer Capability information 
element(s) of the SETUP message. The bearer capability information element(s) shall contain the same 
parameters as received in the SETUP except those presenting a choice. Where choices were offered, appropriate 
parameters indicating the results of those choices shall be included. 

The CALL_PROCEEDING message shall also contain the priority of the call in the case where the network 
supports eMLPP. Mobile stations supporting eMLPP shall indicate this priority level to higher sublayers and 
store this information for the duration of the call for further action. Mobile stations not supporting eMLPP shall 
ignore this information element if provided in a CALL PROCEEDING message. 

NOTE: If the network supports only R98 or older versions of this protocol and the priority is not included in the 
CALL PROCEEDING message, this does not imply that the network does not support eMLPP. 

The CALL_PROCEEDING message shall contain the multicall supported information in the network call 
control capabilities in the case where the network supports multicall and there are no other ongoing calls to the 
MS. Mobile stations supporting multicall shall store this information until the call control state for all calls 
returns to null. Mobile stations not supporting multicall shall ignore this information if provided in a CALL 
PROCEEDING message. If the multicall supported information is not sent in the CALL_PROCEEDING 
message, the mobile station supporting multicall shall regard that the network doesn't support multicall. 

The call control entity of the network having entered the "mobile originating call proceeding" state, the network may 
initiate the assignment of a traffic channel according to subclause 5.2.1.9 (early assignment). 

For speech calls, if the SETUP message or EMERGENCY SETUP message contains a Supported Codec List 
information element, the network shall use this list to select the codec for UTRAN. If no Supported Codec List 
information element is received, then for UTRAN the network shall select the default UMTS speech codec according to 
subclause 5.2.\.\\. 

Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in 
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer 
Capability information element is received, then for GERAN the network shall select GSM full rate speech version L 

Codec information that does not apply to the currently serving radio access shall be used by the network if an inter- 
system change occurs. 
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Figure 5.2/3GPP TS 24.008 Mobile originated call initiation and possible subsequent responses. 



5.2.1.3 



Receipt of a CALL PROCEEDING message 



Having entered the "call initiated" state, when the call control entity of the mobile station receives a CALL 
PROCEEDING message, it shall stop timer T303; start timer T310 unless 

the CALL PROCEEDING message contains s. progress indicator IE specifying progress description #1, #2, or 
#64; or 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 1 225 ETSI TS 1 24 008 V1 0.1 0.0 (201 3-04) 

it has received a PROGRESS message containing a progress indicator IE specifying progress description #1, #2, 
or #64 prior to the CALL PROCEEDING message 

and enter the "mobile originating call proceeding" state. 

Abnormal case: 

If timer T310 elapses before any of the ALERTING, CONNECT or DISCONNECT messages has been received, 
the mobile station shall perform the clearing procedure described in subclause 5.4. 

MS Network 
+ + 



Figure 5.3/3GPP TS 24.008 Call proceeding sequence at mobile originating call establishment 

5.2.1 .4 Notification of progressing mobile originated call 

In this subclause, the term "interworking" is used only in the meaning of interworking with a network other than PLMN 
or ISDN, not as interworking between PLMN and ISDN since this is the normal case. In this sense, PLMN and ISDN 
are seen within the same environment, called the PLMN/ISDN environment. 

5.2.1 .4.1 Notification of interworking in connection with mobile originated call establishment 

During call establishment, the call may leave a PLMN/ISDN environment; e.g., because of interworking with another 
network, with a non-PLMN/ISDN user, or with non-PLMN/ISDN equipment within the called user's premises; the call 
may also return to a PLMN/ISDN environment. When such situations occur, the network may send a progress indicator 
information element to the calling mobile station either: 

a) in an appropriate call control message, if a state change is required (e.g. ALERTING or CONNECT); or, 

b) in the PROGRESS message, if no state change is appropriate. 

This progress /«(i/cflfor information element shall contain one of the following progress description values: 

a) #1 "call is not end-to-end PLMN/ISDN; further call progress information may be available in-band". 

b) #2 "destination address is non-PLMN/ISDN". 

c) #4 "call has returned to PLMN/ISDN. 

See also subclauses 5.5.1 and 5.5.6 for further reactions of the mobile station. 

5.2.1 .4.2 Call progress in the PLMN/ISDN environment 

In order to inform the mobile station that the call is progressing in the PLMN/ISDN environment the network may send 
a progress indicator information element to the calling mobile station either: 

a) in an appropriate call control message, if a state change is required (e.g., ALERTING or CONNECT); or 

b) in the PROGRESS message, if no state change is appropriate. 

This progress indicator information element shall contain progress description value #32 "Call is end-to-end 
ISDN/PLMN". See also subclause 5.5.6 for further reactions of the mobile station. 

5.2.1.5 Alerting 

Having entered the "mobile originating call proceeding" state, upon receiving an indication that user alerting has been 
initiated at the called address, the call control entity of the network shall: send an ALERTING message to its peer entity 
at the calling mobile station and enter the "call delivered" state. 
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When the call control entity of the mobile station in the "call initiated" state or "mobile originating call proceeding" 
state receives an ALERTING message then, the call control entity of the mobile station shall stop timer T303 and T310 
(if running) and shall enter the "call delivered" state. In this state: 

for speech calls: an alerting indication should be given to the user. If the mobile station has not attached the user 
connection then the mobile station shall internally generate an alerting indication. If the mobile station has 
attached the user connection then the network is responsible for generating the alerting indication and the mobile 
station need not generate one; and 

for multimedia calls: if the mobile station has not attached the user connection then the mobile station may 
internally generate an alerting indication. If the mobile station supports multimedia CAT during the alerting 
phase of a mobile originated multimedia call establishment, the network may request the mobile station to attach 
the user connection and setup a H.324 call and generate multimedia CAT as specified in subclause 5.3.6.4, in 
which case the mobile station need not generatean alerting tone. 

Abnormal cases: 

On the mobile station side, if timer T310 expires, the call control entity of the mobile station shall initiate call 
clearing as described in subclause 5.4. 

MS Network 
+ + 



Figure 5.4/3GPP TS 24.008 Call confirmation at mobile originating call establishment 

5.2.1.6 Call connected 

Upon receiving an indication that the call has been accepted, the call control entity of the network shall: through 
connect the traffic channel (including the connection of an interworking function, if required) and send a CONNECT 
message to its peer entity at the calling mobile station; start timer T313 and enter the "connect indication" state. 

This message indicates to the call control entity of the calling mobile station that a connection has been established 
through the network. 

The call control entity of the mobile station in the "call initiated" state, in the "mobile originating call proceeding" state 
or in the "call delivered" state, shall, upon receipt of a CONNECT message: 

attach the user connection; 

- return a CONNECT ACKNOWLEDGE message; 

stop any locally generated alerting indication (if applied); 

clear any H.324 call established to receive multimedia CAT during the alerting phase (if applied) , as specified in 
subclause 5.3.6.4 

stop timer T303 and T310 (if running); 

enter the "active" state. 

Abnormal cases: 

On the mobile station side, if timer T303 or T310 expires, the call control entity of the mobile station shall 
initiate call clearing as described in subclause 5.4. 

NOTE: The mobile station may have applied an additional internal alerting supervision which causes initiation of 
call clearing prior to the expiry of T303 or T3 10. 

The call control of the network in the "connect indication" state, shall, upon receipt of a CONNECT ACKNOWLEDGE 

message: 
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stop timer T313 and enter the "active" state. 

Abnormal cases: 

On the network side, if timer T313 elapses before a CONNECT ACKNOWLEDGE message has been received, 
the network shall perform the clearing procedure as described in subclause 5.4. 

MS Network 

+ + 

CONNECT 
< 

CONNECT ACKNO¥LEDGE 
> 

+ + 

Figure 5.5/3GPP TS 24.008 Call acceptance sequence at mobile originating call establishment 

5.2.1.7 Call rejection 

Upon receiving an indication that the network or the called user is unable to accept the call, the network shall initiate 
call clearing at the radio interface to the mobile which originated the call, as described in subclause 5.4 using the cause 
provided by the terminating network or the called user. 

5.2.1 .8 Transit network selection 

NOTE: For further study. 

5.2.1 .9 Traffic channel assignment at mobile originating call establishment 

The mobile station supporting multicall includes the Stream Identifier (SI) in the SETUP message. The multicall 
supporting network shall interprets the SI value as follows: 

a) Mobile station generates a new SI value at the initiation of an originating call, then a new traffic channel shall be 
assigned to the mobile originating call. 

b) Mobile station indicates an existing SI value, then the indicated traffic channel shall be used for the mobile 
originating call. 

Mobile station supporting multicall shall never send an additional SETUP with indication that a new traffic channel is 
requested to a network that does not support multicall. 

It is a network dependent decision when to initiate the assignment of an appropriate traffic channel during the mobile 
originating call establishment phase. Initiation of a suitable RR procedure to assign an appropriate traffic channel does 
neither change the state of a call control entity nor affect any call control timer. 

NOTE: During certain phases of such an RR procedure, transmission of CC and MM messages may be 
suspended, see 3GPP TS 44.018 [84], clause 3 and 3GPP TS 48.008 [85]. 

The assignment procedure does not affect any call control timer. 

5.2.1 .10 Call queuing at mobile originating call establishment 

If an idle traffic channel is not available at the assignment instant, the network may place the traffic channel request in a 
queue. Calls arriving when all positions in the queue are occupied shall be cleared by the network using the cause #34 
"no circuit/channel available". 

The maximum queuing interval is supervised by the network. The limit is a network dependent choice. In case the 
network is not able to allocate a traffic channel within the queuing limit, the network will release the call using cause 
#34 "no circuit/channel available". 

Optionally, e.g. if eMLPP is used, the network may decide to pre-empt existing calls or to place the traffic channel 
request at some preferential position within the queue. 

Specific indications provided in the network to the remote user are a network dependent choice. 
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5.2.1 .1 1 Speech Codec Selection 

For speech calls, a mobile station implementing this version of the protocol shall indicate all codecs that it supports for 
UTRAN in the Supported Codec List information element. Codecs for GERAN shall be indicated in the Bearer 
Capability information element, if this information element is included. Additionally, if the mobile station supports 
codecs for GERAN and UTRAN, it shall indicate the codecs for GERAN also in the Supported Codec List information 
element. 

If the network does not receive a Supported Codec List information element then for speech calls in UTRAN it shall 
select the default UMTS speech codec. 

For speech calls in GERAN, if the network does not receive a Supported Codec List information element nor a Bearer 
Capability information element, the network shall select GSM full rate speech version 1. 

The network shall determine the default UMTS speech codec by the following: 

i) If no GSM Speech Version codepoints are received in the Supported Codec List IE or in octet 3a etc. of the 
Bearer Capabilities IE then a "UMTS only" terminal is assumed and the default UMTS speech codec shall be 
UMTS_AMR. 

ii) If at least one GSM Speech Version codepoint is received in the Supported Codec List IE or in octet 3a etc. of 
the Bearer Capabilities IE then the ME supports GSM and UMTS and the default UMTS speech codec shall be 
UMTS_AMR_2. 

NOTE 1 : In case (ii), if the call is set up in A/Gb or GERAN lu mode by a R99 ME, call control in the core 

network may treat the ME as a "GSM only" ME. The default UMTS speech codec will only become 
relevant when an intersystem handover to UTRAN lu mode is initiated by the radio access network, and 
can be determined when this procedure is started. 

If the Supported Codec List IE is received, then the network shall use this list to select the codec for lu mode and 
indicate the selected codec to the ME via RANAP and RRC protocol in the NAS Synchronisation Indicator IE. See 
3GPPTS 25.413 [19c], 3GPPTS 25.331 [23c] and 3GPPTS 44.118 [111]. 

The NAS Synchronisation Indicator IE shall be coded as the 4 least significant bits of the selected codec type (CoID) 
defined in 3GPP TS 26.103 [83], subclause 6.3. 

The network shall determine the preference for the selected codec type; codec type prioritisation is not provided by the 
ME. 

The ME shall activate the codec type received in the NAS Synchronisation Indicator IE. 

If the mobile station does not receive the NAS Synchronisation Indicator IE (RRC protocol) 

during setup of a speech call; 

during inter-system handover of a speech call from A/Gb or GERAN lu mode to UTRAN lu mode; or 

during an in-call modification from data to speech, 

then it shall select the UMTS_AMR_2 speech codec. 

NOTE 2: If the network does not support UMTS_AMR_2, it may activate the UMTS_AMR codec and indicate to 
the mobile station that it shall select UMTS_AMR_2. According to 3GPP TS 26.103 [83], subclause 5.4, 
no interworking problem will occur in this case. 

If the mobile station has selected a speech codec for UTRAN lu mode, it shall keep this codec until 

a new codec is requested by the network by sending a NAS Synchronisation Indicator IE (RRC protocol); 

a new codec is requested by the network during inter-system handover from UTRAN lu mode to A/Gb or 
GERAN lu mode; or 

an in-call modification from speech to data is performed. 
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For adaptive multirate codec types no indication of subsets of modes is supported in this protocol, from the mobile 
station or to the mobile station. It is a pre-condition that the support of such codec types by the mobile station implicitly 
includes all modes defined for that codec type. 

5.2.1 .12 Cellular Text telephone Modem (CTM) selection 

The mobile station can send a CTM support indication in the Bearer Capability IE in call establishment messages to 
inform the network of the use of CTM text in the call. 

When the mobile station indicates speech and support of CTM text telephony, the network shall select a speech codec 
and additionally CTM text telephony detection/conversion functions as specified in 3GPP TS 23.226 [92] and 
3GPP TS 26.226 [93], if such functions are available. 

NOTE: If CTM support is indicated by the mobile station, then it supports CTM text telephony together with any 
supported speech codec and for any supported radio access. 

5.2.2 Mobile terminating call establishment 

Before call establishment can be initiated in the mobile station, the MM connection must be established by the network. 



5.2.2.1 



Call indication 



After the arrival of a call from a remote user, the corresponding call control entity in the network shall: initiate the MM 
connection establishment according to clause 4 and enter the "MM connection pending" state. The request to establish 
the MM connection is passed from the CM sublayer to the MM sublayer. It contains the necessary routing information 
derived from the SETUP message. 

Upon completion of the MM connection, the call control entity of the network shall: send the SETUP message to its 
peer entity at the mobile station, start timer T303 and enter the "call present" state. 

The SETUP message shall contain the multicall supported information in the network call control capabilities in the 
case where the network supports multicall and there are no other ongoing calls to the MS. Mobile stations supporting 
multicall shall store this information until the call control state for all calls returns to null. Mobile stations not 
supporting multicall shall ignore this information if provided in a SETUP message. If the multicall supported 
information is not sent in the SETUP message, the mobile station supporting multicall shall regard that the network 
does not support multicall. 

Upon receipt of a SETUP message, the mobile station shall perform compatibility checking as described in 
subclause 5.2.2.2. If the result of the compatibility checking was compatibility, the call control entity of the mobile 
station shall enter the "call present" state. An incompatible mobile station shall respond with a RELEASE COMPLETE 
message in accordance with subclause 5.2.2.3.4. 

If there are no bearer capability lEs in the SETUP message, the network may provide information about the requested 
service in the backup bearer capability IE. 

If no response to the SETUP message is received by the call control entity of the network before the expiry of timer 
T303, the procedures described in subclause 5.2.2.3.3 shall apply. 
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Figure 5.6/3GPP TS 24.008 Mobile terminating call initiation and possible subsequent responses. 
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5.2.2.2 Compatibility checking 

The mobile station receiving a SETUP message shall perform compatibility checking before responding to that SETUP 
message. Annex B defines compatibility checking to be performed by the mobile station upon receiving a SETUP 
message. For a backup bearer capability IE received with a SETUP message the mobile station shall not perform 
compatibility checking as described in annex B. 

5.2.2.3 Call confirmation 

5.2.2.3.1 Response to SETUP 

Having entered the "call present state" the call control entity of the mobile station shall - with the exception of the cases 
described below - acknowledge the SETUP message by a CALL CONFIRMED message, and enter the "mobile 
terminating call confirmed" state. 

If the mobile station supports multicall, it shall include the Stream Identifier (SI) information element in the CALL 
CONFIRMED message. 

If the mobile station is located in the network supporting multicall, it shall never include the SI that is in use and 
shall include with either of the following two values: 

SI="no bearer"; 

SI=new value (not used by any of the existing bearers). 

If the mobile station supporting multicall is located in the network not supporting multicall, it shall include the SI with 
value 1. 

The call control entity of the mobile station may include in the CALL CONFIRMED message to the network one or 
two bearer capability information elements to the network, either preselected in the mobile station or corresponding to a 
service dependent directory number (see 3GPP TS 29.007 [38]). The mobile station may also use the backup bearer 
capability IE, if provided by the network, to deduce the requested service (see 3GPP TS 27.001 [36], subclause 8.3.3.1). 
The mobile station may also include one or two bearer capabilities in the CALL CONFIRMED message to define the 
radio channel requirements. In any case the rules specified in subclause 9.3.2.2 shall be followed. 

NOTE: The possibility of alternative responses (e.g., in connection with supplementary services) is for further 
study. 

For speech calls the mobile station shall indicate all codecs that it supports for UTRAN in the Supported Codec List 
information element. Codecs for GERAN shall be indicated in the Bearer Capability information element, if this 
information element is included. Additionally, if the mobile station supports codecs for GERAN and UTRAN, it shall 
indicate the codecs for GERAN also in the Supported Codec List information element. 

If the MS supports the enhanced network-initiated in-call modification procedure as specified in subclause 5.3.4.3, the 
MS shall indicate this in the Call Control Capabilities IE in the CALL CONFIRMED message. 

A busy MS which satisfies the compatibility requirements indicated in the SETUP message shall respond either with a 
CALL CONFIRMED message if the call setup is allowed to continue or a RELEASE COMPLETE message if the call 
setup is not allowed to continue, both with cause #17 "user busy". 

If the mobile user wishes to refuse the call, a RELEASE COMPLETE message shall be sent with the cause #21 "call 
rejected". 

In the cases where the mobile station responds to a SETUP message with RELEASE COMPLETE message the mobile 
station shall release the MM connection and enter the "null" state after sending the RELEASE COMPLETE message. 

The network shall process the RELEASE COMPLETE message in accordance with subclause 5.4. 

5.2.2.3.2 Receipt of CALL CONFIRMED and ALERTING by the network 

The call control entity of the network in the "call present" state, shall, upon receipt of a CALL CONFIRMED message: 
stop timer T303, start timer T310 and enter the "mobile terminating call confirmed" state. 
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In lu mode, network shall include the SI received in the CALL CONFIRMED message into the RABid and send it back 
to the mobile station. For RABid see 3GPP TS 25.413 [19c] and 3GPP TS 44. 1 18 [1 1 1]. If the network receives the 
CALL CONFIRMED message with no SI, the network shall set the SI value to 1. 

For speech calls, if the CALL CONFIRMED message contains a Supported Codec List information element, the 
network shall use this list to select the codec for UTRAN. If no Supported Codec List information element is received, 
then for UTRAN the network shall select the default UMTS speech codec according to subclause 5.2.1.1 1. 

Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in 
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer 
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1. 

Codec information that does not apply to the currently serving radio access shall be used by the network if an inter- 
system change occurs. 

The call control entity of the mobile station having entered the "mobile terminating call confirmed" state, if the call is 
accepted at the called user side, the mobile station proceeds as described in subclause 5.2.2.5. Otherwise, if the signal 
information element was present in the SETUP message user alerting is initiated at the mobile station side; if the signal 
information element was not present in the SETUP message, user alerting is initiated when an appropriate channel is 
available. 

Here, initiation of user alerting means: 

the generation of an appropriate tone or indication at the mobile station; and 

sending of an ALERTING message by the call control entity of the MS to its peer entity in the network and 
entering the "call received" state. 

The call control entity of the network in the "mobile terminated call confirmed" state shall, upon receipt of an 
ALERTING message: send a corresponding ALERTING indication to the calling user; stop timer T310; start timer 
T301, and enter the "call received" state. 

In the "mobile terminating call confirmed" state or the "call received" state, if the user of a mobile station is User 
Determined User Busy then a DISCONNECT message shall be sent with cause #17 "user busy". In the "mobile 
terminating call confirmed" state, if the user of a mobile station wishes to reject the call then a DISCONNECT message 
shall be sent with cause #21 "call rejected". 

5.2.2.3.3 Call failure procedures 

In case of abnormal behaviour the following call failure procedures apply: 

i. If the network does not receive any response to the SETUP message prior to the expiration of timer T303, then 
the network shall: initiate clearing procedures towards the calling user with cause #18 "no user responding"; and 
initiate clearing procedures towards the called mobile station in accordance with subclause 5.4.4 using cause 
#102 "recovery on timer expiry". 

ii. If the network has received a CALL CONFIRMED message, but does not receive an ALERTING, CONNECT 
or DISCONNECT message prior to the expiration of timer T310, then the network shall: 

initiate clearing procedures towards the calling user with cause #18 "no user responding"; and 

initiate clearing procedures towards the called MS in accordance with subclause 5.4.4 using cause #102 
"recovery on timer expiry" . 

iii. If the network has received an ALERTING message, but does not receive a CONNECT or DISCONNECT 

message prior to the expiry of timer T301 (or a corresponding internal alerting supervision timing function), then 
the network shall: initiate clearing procedures towards the calling user with cause #19 "user alerting, no answer"; 
and initiate clearing procedures towards the called mobile station in accordance with subclause 5.4.4, using 
cause #102 "recovery on timer expiry" or using cause #31 "normal, unspecified". 

NOTE: The choice between cause #31 and cause #102 may have consequences on indications generated by the 
mobile station, see 3GPPTS 22.001 [8a]. 
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5.2.2.3.4 Called mobile station clearing during mobile terminating call establishment 

See subclause 5.4.2. 

5.2.2.4 Notification of interworking in connection with mobile terminating call 
establishment 

In this subclause, the term "interworking" is used only in the meaning of interworking with a network other than PLMN 
or ISDN, not as interworking between PLMN and ISDN since this is the normal case. In this sense, PLMN and ISDN 
are seen within the same environment, called the PLMN/ISDN environment. 

During call establishment the call may enter an PLMN/ISDN environment, e.g., because of interworking with another 
network, with a non-PLMN/ISDN user, or with non-PLMN/ISDN equipment within the calling or called user's 
premises. When this occurs, the network may include a progress indicator information element to be included in the 
SETUP message to be sent to the called mobile station specifying progress description value: 

a) #1 "call is not end-to-end PLMN/ISDN; further call progress information may be available in-band" or 

b) #3 "origination address is non-PLMN/ISDN". 

See also subclause 5.5. 1 for further reactions of the mobile station. 

5.2.2.5 Call accept 

In the "mobile terminating call confirmed" state or the "call received" state, the call control entity in the mobile station 
indicates acceptance of a mobile terminating call by: 

sending a CONNECT message to its peer entity in the network; 

starting Timer T3 1 3 ; and 

entering the "connect request" state. 

If the call control entity of the mobile station has indicated "No Bearer" as the SI value in the CALL CONFIRMED 
message, it shall assign the SI value and include the SI information element in the CONNECT message. Otherwise the 
SI information element shall not be included in the CONNECT message. 

5.2.2.6 Active indication 

In the "mobile terminated call confirmed" state or in the "call received" state, the call control entity of the network shall, 
upon receipt of a CONNECT message: through connect the traffic channel (including the connection of an interworking 
function, if required), stop timers T310, T303 or T301 (if running); send a CONNECT ACKNOWLEDGE message to 
its peer entity at the mobile station of the called user; initiate procedures to send a CONNECT message towards the 
calling user and enter the "active" state. 

In the "connect request" state, the call control entity of the mobile station shall, upon receipt of a CONNECT 
ACKNOWLEDGE message: stop timer T313 and enter the "active" state. 

When timer T313 expires prior to the receipt of a CONNECT ACKNOWLEDGE message, the mobile station shall 
initiate clearing in accordance with subclause 5.4.3. 

US Network 
+ + 
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CONNECT ACKNOWLEDGE 
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+ + 

Figure 5.7/3GPP TS 24.008 Call acceptance and active indication at mobile terminating call 

establishment 
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5.2.2.7 Traffic channel assignment at mobile terminating call establishment 

After receiving the SETUP message, the mobile station supporting multicall may either require a new traffic channel or 
reuse an existing traffic channel. 

If a mobile station in the network supporting multicall requires a new traffic channel, it shall: 

send a CALL CONFIRMED message including the SI indicating a new value, not used by any of the existing 
traffic channels. 

If a mobile station in the network supporting multicall does not require a new traffic channel, it shall: 

send a CALL CONFIRMED message including the SI equal to "no bearer". 

After the mobile station has send the CALL CONFIRMED with SI="no bearer", the SI value in the CONNECT 
message will tell to the network if a user requests a new traffic channel or one of the existing ones will be re-uesd. 

If a new traffic channel is requested by the user, the mobile station in the network supporting multicall shall: 

send a CONNECT message containing the SI with a new value, not used by any existing traffic channel. 

If the user decides that an existing traffic channel will be reused, the mobile station in the network supporting multicall 
shall: 

send a CONNECT message with an SI indicating an existing value used by an existing traffic channel. 

It is a network dependent decision when to initiate the assignment of a traffic channel during the mobile terminating call 
establishment phase. 

Initiation of the assignment phase does not directly change the state of a CC entity nor affect any call control timer, but 
may have some secondary effects (see e.g. subclause 5.2.2.3.2). 

5.2.2.8 Call queuing at mobile terminating call establishment 

The principles described in subclause 5.2.1.10 apply accordingly. 

NOTE: The interworking to the fixed network has to fulfil the network specific requirements. 

5.2.2.9 User connection attachment during a mobile terminating call 

For speech calls: 

The mobile station shall attach the user connection at latest when sending the connect message. 

For data calls: 

The mobile station shall attach the user connection when receiving the CONNECT ACKNOWLEDGE message 
from the network. 

5.2.2.1 Speech Codec Selection 

The principles described in subclause 5 .2. 1 . 11 apply accordingly. 

5.2.2.1 1 Cellular Text telephone Modem (CTM) selection 

The principles described in subclause 5.2.1.12 apply accordingly. 
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5.2.3 Network initiated MO call $(CCBS)$ 

The procedures of subclause 5.2.3 are mandatory for mobile stations supporting "Network initiated MO call". 

NOTE: The behaviour of a mobile station that does not support "Network initiated MO call" is described in 
clause 4. 

5.2.3.1 Initiation 

Before call establishment can be initiated in the mobile station, the MM connection shall be established by the network. 

After the arrival of an appropriate stimulus (for example a Remote User Free Indication), the corresponding call control 
entity in the network shall initiate the MM connection establishment according to clause 4, enter the "CC connection 
pending" state and start timer T331. The request to establish the MM connection is passed from the CM sublayer to the 
MM sublayer. It contains the necessary routing information derived from the received stimulus. 

Upon completion of the MM connection, the call control entity of the mobile station shall send a START CC message 
to its peer entity in the network. The mobile station shall then enter the "Wait for network information" state and start 
timer T332. 

If the network receives a START CC message while in the "CC connection pending" state, the network stops T33 1 , 
sends the CC-ESTABLISHMENT message, starts timer T333 and enters the "CC -establishment present" state. 

The MM connection establishment may be unsuccessful for a variety of reasons, in which case the MM sublayer in the 
network will inform the CC entity in the network with an indication of the reason for the failure. The CC entity shall 
then stop all running timers, enter the "Null" state and inform all appropriate entities within the network. 

If timer T331 expires, the network shall abort the MM connection establishment attempt, stop all running CC timers, 
enter the "Null" state and inform all appropriate entities within the network. 

5.2.3.2 CC-Establishment present 

In the "CC establishment present" state, the mobile station, upon receipt of the CC-ESTABLISHMENT message, shall 
stop timer T332. 

The CC-ESTABLISHMENT message contains information which the mobile station shall use for the subsequent 
SETUP message (if any) related to this CC-ESTABLISHMENT. 

The CC-ESTABLISHMENT message shall contain the Setup Container IE. 

If no CC-ESTABLISHMENT message is received by the call control entity of the mobile station before the expiry of 
timer T332, then the mobile station shall initiate clearing procedures towards the network using a RELEASE 
COMPLETE message with cause #102 "recovery on timer expiry" and proceed in accordance with subclause 5.4.2. 

Upon receipt of a CC-ESTABLISHMENT message the mobile station shall perform checks on the Setup Container IE 
in order to align the contained information with the mobile's present capabilities and configuration. The "recall 
alignment procedure" is defined later on in this subclause. 

If the recall alignment procedure has succeeded, the call control entity of the Mobile Station shall: 
form and store the SETUP message for sending later in the "Recall present" state, 
- acknowledge the CC-ESTABLISHMENT message with a CC-ESTABLISHMENT CONFIRMED message, 
start timer T335, and 
enter the "CC-establishment confirmed" state. 

Exception: 

A busy mobile station which has successfully performed the recall alignment procedure shall respond with a CC- 
ESTABLISHMENT CONFIRMED message with cause #17 "user busy", and proceed as stated above. 

For speech calls the mobile station shall indicate all codecs that it supports for UTRAN in the Supported Codec List 
information element of the CC-ESTABLISHMENT CONFIRMED message. Codecs for GERAN shall be indicated in 
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the Bearer Capability information element. Additionally, if the mobile station supports codecs for GERAN and 
UTRAN, it shall indicate the codecs for GERAN also in the Supported Codec List information element. 

A mobile station, for which the recall alignment procedure failed, shall respond with a RELEASE COMPLETE 
message in accordance with subclause 5.4.2 with the appropriate cause code as indicated in the description of the recall 
alignment procedure. 

The SETUP message is constructed from the Setup Container IE received in the CC ESTABLISHMENT MESSAGE. 
The mobile station shall assume that the Setup Container IE contains an entire SETUP message with the exception of 
the Protocol Discriminator, Transaction ID and Message Type elements. The mobile station may assume that the 
contents of the Setup Container IE are the same as were sent from the subscriber in a previous SETUP message of the 
mobile originating call establishment attempt. The mobile station shall copy the Setup Container to the SETUP message 
and not modify the contents except as defined in the recall alignment procedure and as defined in exceptions below. The 
mobile station shall not add other Information Elements to the end of the SETUP message. 

Exceptions: 

Bearer Capability IE(s), HLC IE(s) and LLC IE(s) (including Repeat Indicator(s), if there are 2 bearer 
capabilities), and the Supported Codec List IE require handling as described in the recall alignment procedure 
below. 

If the CC Capabilities in the Setup Container IE is different to that supported by the mobile station, the mobile 
station shall modify the CC Capabilities in the SETUP message to indicate the true capabilities of the mobile 
station. 

Facility IE(s) and SS Version IE(s) require handling as described in the recall alignment procedure. 

Stream Identifier IE requires handling as described in the recall alignment procedure. 

If no response to the CC -ESTABLISHMENT message is received by the call control entity of the network before the 
expiry of timer T333, then the network shall initiate clearing procedures towards the called mobile station using a 
RELEASE COMPLETE message with cause #102 "recovery on timer expiry" and inform all appropriate entities within 
the network, proceeding in accordance with subclause 5.4.2. 
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Figure 5.7a/3GPP TS 24.008 Call initiation and possible subsequent responses. 

5.2.3.2.1 Recall Alignment Procedure 

The recall alignment procedure consists of three parts: 

basic service group alignment, 

facility alignment, and 

stream identifier alignment. 

Basic service group alignment: 

The mobile station shall check that the Bearer Capability, HLC and LLC and Repeat Indicator fields, which are 
embedded in the Setup Container IE, match a basic service group supported by the mobile station. 

If this check fails, then the recall alignment procedure has failed. The mobile station shall use the cause #88 
"incompatible destination" afterwards. 
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Otherwise, the mobile station is allowed to alter the content within the Bearer Capability, HLC and LLC Information 
Elements (e.g. the speech codec version(s), the data rate, the radio channel requirement) provided that the basic service 
group is not changed. Furthermore, for speech calls the mobile station is allowed to add or remove the Supported Codec 
List Information Element, or to alter the contents of this information element dependent on the codecs supported by the 
mobile station. The result shall be that the mobile station has derived Bearer Capability, HLC, LLC, and Supported 
Codec List Information Elements, which it can use for a later call setup according to its configuration and capabilities. 

Facility alignment: 

This only applies if the Setup Container contains 1 or more Facility IBs. Each Facility IE within the Setup 
Container will be associated with the common SS Version IE, if present. The handling for each Facility IE is 
defined below. The mobile station shall align each facility IE contained in the Setup Container. The rules defined 
in 3GPP TS 24.010 [21] also apply. 

The Facility IE is encoded as 'simple recall alignment', 'advanced recall alignment' or 'recall alignment not essential' 
(see 3GPP TS 24.010 [21]). If the encoding indicates, that 

a simple recall alignment is required, the mobile station shall copy the Facility IE and the common SS version IE 
from the Setup Container to the SETUP message without modifying the content. 

an advanced recall alignment is required, the mobile station must recognise and support the operation defined in 
the facility. If the mobile station does not recognise or support the operation, then the recall alignment procedure 
has failed and the mobile station shall use the cause #29 "facility rejected" in the subsequent rejection of the CC 
establishment request. 

the recall alignment is not essential, then the facility operation is not an essential part of the SETUP. If the MS 
does not recognise the operation then the SS Version IE and Facility IE are discarded, and NOT copied into the 
SETUP message. 

NOTE: A mobile station may include a Facility IE without an associated SS Version IE. This would indicate that 
the SS operation is encoded using Phase 1 protocols. 

Further details on Facility handling are given in 3GPP TS 24.010 [21]. 

Stream identifier alignment: 

The mobile station shall check whether the Stream Identifier field is contained in the Setup Container or nof. 

If the Stream Identifier is contained in the Setup Container, the mobile station shall behave as one of the following. 

the mobile station re-assign the Stream Identifier value, and modify the Stream Identifier field. 

the mobile station remove the Stream Identifier field. 

If the Stream Identifier is not contained in the Setup Container, the mobile station may behave as follows. 

the mobile station assign the Stream Identifier value, and add the Stream Identifier IE to the end of the SETUP 
message. 

5.2.3.3 CC-Establishment confirmation 

The call control entity of the network in the "CC -establishment present" state, shall, upon receipt of a CC- 
ESTABLISHMENT CONFIRMED message, stop timer T333 and enter the "CC-establishment confirmed" state. 

For speech calls, if the ESTABLISHMENT CONFIRMED message contains a Supported Codec List information 
element, the network shall use this list to select the codec for UMTS. If no Supported Codec List information element is 
received, then for UMTS the network shall select the default UMTS speech codec according to subclause 5. 2. 1.11. 

Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in 
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer 
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1. 

Codec information that does not apply to the currently serving radio access shall be used by the network if an inter- 
system change occurs. 
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In the "CC-establishment confirmed" state, the network sends a RECALL message. This message initiates user alerting 
and also shall include the Facility IE (providing additional information to be presented to the user for notification). The 
network starts timer T334 and enters the 'recall present' state. 

Upon reception of the RECALL message the Mobile station stops T335 and enters the "recall present" state. 



Network 

+ 



Figure 5.7b/3GPP TS 24.008 Recall 

5.2.3.4 Recall present 

In the "recall present" state, the call control entity in the mobile station waits for acceptance of the Recall by the user. 
Once confirmation is received, the mobile station indicates acceptance of a recall by 

sending a SETUP message to its peer entity in the network; 

starting Timer T303; and 

entering the "call initiated" state and proceeding as described in subclause 5.2.1.1. 

The MS shall ensure that the contents of the Bearer Capability IE(s) and Supported Codec List IE sent in the SETUP 
message are the same as the Bearer Capability IE(s) and Supported Codec List IE in the previous CC- 
ESTABLISHMENT CONFIRMED message related to this Network Initiated MO Call. 

In the "recall-present" state, if the user of a mobile station is User Determined User Busy then a RELEASE 
COMPLETE message shall be sent with cause #17 "user busy" In the "recall-present" state. If the user of a mobile 
station wishes to reject the recall then a RELEASE COMPLETE message shall be sent with cause #21 "call rejected". 

In either case, the mobile shall release the connection in accordance with subclause 5.4.2 

On receipt of the SETUP message in the "recall present" state, the network shall stop timer T334 and proceed as 
specified in subclause 5.2.1.2. 

If the call control entity of the network does not receive a SETUP message before the expiry of timer T334, then the 
network shall send a RELEASE COMPLETE message to the mobile using cause #102 "recovery on timer expiry", 
release the MM connection, enter the "null" state and shall inform all appropriate entities within the network. 
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Flgure 5.7b/3GPP TS 24.008 Recall acceptance or rejection by user 

5.2.3.5 Traffic channel assignment during network initiated mobile originating call 

establishment 

It is a network dependent decision whether or not to initiate the assignment of a traffic channel during the "CC- 
establishment confirmed" state. 
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5.2.4 Call establishment for SRVCC 

5.2.4.1 General 

Before call establishment for SRVCC can be initiated in the mobile station, the MM connection must be established by 
the network. 

At PS to CS domain change from SI mode or lu mode due to SRVCC handover (see 3GPP TS 23.216 [126]), the RR 
sublayer in the MS delivers the handover indication to the MM sublayer. At reception of the indication, the MS that 
supports SRVCC shall establish an MM connection as specified in subclause 4.5.1.8. 

5.2.4.2 Call activation 

If the MS supports SRVCC and the MS has a voice media stream carried over the PS domain that is handed over to the 
CS domain via SRVCC, and the session is in the "confirmed" state (defined in IETF RFC 3261 [137]), and the call 
control entity in "null" state receives indication "MM connection establishment due to SRVCC handover", the call 
control entity of the MS shall enter the "active" state and indicate the call establishment to upper layers. The MS and the 
network shall locally set the TI value of the call to "000" and the TI flag value as in mobile terminated call. If a single 
voice media stream is handed over and the session is on hold, the setting of the auxiliary state (as defined in 
3GPP TS 24.083 [27]) is described in 3GPP TS 24.237 [136]. 

If the MS supports single radio PS to CS access transfer for calls in alerting state as specified in 3GPP TS 24.237 [136] 
subclause 12.2.3B, and the MS has a single voice media stream over the PS domain that is handed over to the CS 
domain via SRVCC, and the call control entity in "null" state receives an indication "MM connection establishment due 
to SRVCC handover", then: 

if the voice media stream is associated with a mobile originated session in the "early" state (defined in 
IETF RFC 3261 [137]) according to the conditions specified in 3GPP TS 24.237 [136] subclause 12.2.3B.3.2, 
the call control entity of the MS shall enter the "call delivered" state for this transaction. The MS and the 
network shall locally set the TI value of the call to "000" and the TI flag value as in mobile terminated call; and 

if the voice media stream is associated with a mobile terminating session in the "early" state (defined in 
IETF RFC 3261 [137]) according to the conditions specified in 3GPP TS 24.237 [136] subclause 12.2.3B.3.1, 
the call control entity of the MS shall enter the "call received" state for this transaction. The MS and the network 
shall locally set the TI value of the call to "000" and the TI flag value as in mobile terminated call. 

If the MS has additional voice media streams carried over the PS domain that are handed over to the CS domain via 
SRVCC, the state for the transactions and the setting of the TI value and TI flag for these additional media streams is 
described in 3GPP TS 24.237 [136]. 

If the MS supports multicall, the MS shall locally set SI value to 1 and the MS shall assume that the network does not 
support multicall. The network shall also locally set SI value to 1 . 

If the MS has a mobile originating session in the "early" state (as defined in IETF RFC 3261 [137]) and is providing an 
internally generated alerting indication to the user prior to the SRVCC handover, then after transitioning from the PS 
domain, the MS shall continue to provide the internal alerting indication to the user. The alerting indication is stopped 
when the user connection is attached. 

5.2.4.3 Traffic channel assignment and user connection attachment 

An appropriate traffic channel for the SRVCC call is assigned in SRVCC handover. 

For SRVCC handover, the mobile station shall attach the user connection; 

when the call control entity enters the "active" state or the "call received" state; and 

when the call control entity enters the "call delivered" state, if prior to SRVCC the MS in the PS domain was 
receiving media for the session subjected to SRVCC handover. 

NOTE: The attachment of the user connection prior to entering the "active" state allows the network to provide 
in-band tones and announcements to the UE. 

The principles of speech codec selection are described in subclause 5.2.1.11. 
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5.2.4.4 State verification 

The network may check the call and auxiliary states of its peer entity as specified in subclause 5.5.3. 1 when the PS to 
CS access transfer is complete. 

5.3 Signalling procedures during the "active" state 

5.3.1 User notification procedure 

The mobile terminating user notification procedure allows the network to notify a mobile station of any appropriate 
call-related event during the "active" state of a call. The procedure consists in the network sending a NOTIFY message 
to the mobile station. No state change occurs at any of the interface sides following the sending or the receipt of this 
message (but an appropriate indication may optionally be generated in the mobile station). 

The mobile originating notification procedure allows the mobile station to notify the remote user of any appropriate 
call-related event during the "active" state of a call by sending a NOTIFY message containing a notification indicator to 
the network; upon receipt of this message, the network sends a NOTIFY message containing the same notify indicator 
to the other user involved in the call. No state change occurs at any of the interface sides following the sending or the 
receipt of this message. 

5.3.2 Call rearrangements 

Call rearrangements on the radio interface are not supported by explicit messages (e.g. SUSPEND and RESUME 
messages as defined in ETSI ETS 300 102-1 [70]). However if a remote non-PLMN user initiates call rearrangements, 
the network shall inform the mobile station by means of a NOTIFY message. In a similar way the mobile station can 
inform the network about rearrangements by sending a NOTIFY message (e.g. change of user equipment connected to 
the mobile station). 

5.3.3 Codec Change Procedure 

During a speech call in UMTS, if a mobile station supports more than one UMTS codec, the network can change the 
UMTS codec via RRC procedures. In order to request the mobile station to change the codec, the network shall send the 
new selected codec type in the NAS Synchronisation Indicator IE (RRC protocol), see subclause 5. 2. 1.11. 

5.3.4 Support of Dual Services 

The behaviour described in this subclause is used to realize the following required services throughout subclause 5.3.4. 
The mobile station is not obliged to support the network originated in-call modification procedure. In that case, the 
mobile station shall, when receiving a MODIFY message, treat the message as unknown and react as described in 
subclause 8.4. If the mobile station is already prepared to support the procedure in both directions, it shall act as 
described in this subclause. 

Alternate Speech/Group 3 fax (Teleservice 61 according to 3GPP TS 22.003 [4]). 

5.3.4.1 Service Description 

This circuit switched service allows the two users on a point-to-point connection to use the connection between them 
for different information transfer during the same call, but not at the same time. 

If the negotiation during call establishment leads to the recognition of the above mentioned services, the in-call 
modification procedure is allowed to be executed within the current call by changing from one call mode to the other. 

In some cases the in-call modification procedure makes it necessary to change the channel configuration by allocating a 
new channel and in other cases to change channel configuration parameters while keeping the previously allocated 
channel. This change is determined by the network, which initiates either the channel assignment procedure, handover 
procedure or channel mode modify procedure (see clause 3). 



ETSI 



3GPP TS 24.008 version 1 0.10.0 Release 1 240 ETSI TS 1 24 008 V1 0.1 0.0 (201 3-04) 

The capability and the initial mode desired must be identified by the mobile station by identifying each mode of 
operation with a separate information element during call establishment. Further the type of change between the modes 
must be identified by means of the repeat indicator: 

mode 1 "alternate" mode 2. 

5.3.4.2 Call establishment 

For both mobile originating and mobile terminating calls, the normal call establishment procedures apply. 

5.3.4.2.1 Mobile Originating Establishment 

The service is requested by the originating mobile station by transferring a SETUP message to the network containing 
the BC repeat indicator IE, the bearer capability 1 information element, and the bearer capability 2 information 
element. The first mode of operation ("call mode") shall be indicated by the bearer capability 1 information element 
and the second call mode by the bearer capability 2 information element. 

A low layer compatibility may optionally be specified for each call mode in a low layer compatibility I and low layer 
compatibility II information element. In that case: 

the SETUP message shall contain the LLC repeat indicator IE and both low layer compatibility I and low layer 
compatibility II information elements. The low layer compatibility I information element then corresponds to the 
bearer capability 1 information element and the low layer compatibility II information element to the bearer 
capability 2 information element; 

if no low layer compatibility specification applies for one of the two call modes, the corresponding low layer 
compatibility IE (low layer compatibility I or low layer compatibility II) shall indicate "not applicable"; 

the LLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE. 

Similarly, a high layer compatibility may optionally be specified for each call mode in a high layer compatibility i and 
high layer compatibility ii information element. In that case: 

the SETUP message shall contain the HLC repeat indicator IE and both high layer compatibility i and high layer 
compatibility ii information elements. The high layer compatibility i information element then corresponds to the 
bearer capability 1 information element and the high layer compatibility ii information element to the bearer 
capability 2 information element; 

if no high layer compatibility specification applies for one of the two call modes, the corresponding high layer 
compatibility IE {high layer compatibility i or high layer compatibility ii) shall indicate "not applicable"; 

the HLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE. 

The receiving entity shall ignore whether the LLC repeat indicator IE or HLC repeat indicator are contained in the 
message or not; it shall also ignore the repeat indication of an LLC repeat indicator IE or HLC repeat indicator IE. If 
the low layer compatibility II IE is not contained in the message and the low layer compatibility I IE is contained in the 
message, the receiving entity shall relate it to a call mode indicated in the message that does not specify speech (if any). 
If the high layer compatibility ii IE is not contained in the message and the high layer compatibility i IE is contained in 
the message, the receiving entity shall relate it to a call mode indicated in the message that does not specify speech (if 
any). 

The specific part of the network which is sensitive to the call mode shall examine each mode described in the bearer 
capabilities included in the SETUP message by performing compatibility checking as defined in Annex B. If as a result 
of this compatibility checking the network decides to reject the call, then the network shall initiate call clearing as 
specified in subclause 5.4 with the following causes: 

a) #57 "bearer capability not authorized"; 

b) #58 "bearer capability not presently available"; 

c) #65 "bearer service not implemented"; 

d) #70 "only restricted digital information bearer capability is available". 
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5.3.4.2.2 Mobile Terminating Establishment 

The service is indicated to the called mobile station by a SETUP message coded in the same manner as in the mobile 
originating call establishment. As specified for normal terminating call establishment, the service may be indicated by 
the called mobile station in the CALL CONFIRMED message. 

The destination mobile station shall perform the compatibility checking as defined in Annex B for both required modes 
if indicated in the SETUP message. If as a result of compatibility checking the mobile station decides to reject the call, 
the mobile station shall initiate call clearing according to the procedures of subclause 5.4 with one of the following 

causes: 

a) #57 "bearer capability not authorized"; 

b) #58 "bearer capability not presently available"; 

c) #65 "bearer service not implemented"; 

d) #88 "incompatible destination". 

The mobile station may accept the call if the first mode indicated is free irrespective of whether the other mode is free 
or busy. 

5.3.4.3 Changing the Call Mode 

In order to change the call mode, the following in-call modification procedures shall be used. 

Either side of the radio interface may act as the requesting user to invoke the in-call modification. 

Upon each successful completion of the in-call modification procedure, the call changes to the next mode negotiated 
and agreed during the establishment phase of the call. 

The in-call modification procedures are completely symmetrical at the radio interface. 

5.3.4.3.1 Initiation of in-call modification 

The procedure is initiated by the requesting originating side in the "active" state of the call. It shall send a MODIFY 
message including the new mode to be changed to. The requesting originating side shall also start timer T323 and enter 
the "mobile originating modify" state (mobile station side) or the "mobile terminating modify" state (network side). The 
new mode given in the MODIFY message shall be one of those already negotiated and agreed during the establishment 
phase of the call. If the data call direction is different from the direction of the call setup a reverse call setup direction IE 
shall be included in the MODIFY message; otherwise this IE shall not be included. 

If the in-call modification is originated by the mobile station, the mobile station shall reserve any internal resources 
necessary to support the next call mode, stop sending Bm-channel information; and stop interpreting received Bm- 
channel information according to the old call mode. 

If the in-call modification is originated by the network, the network may reserve any internal resources necessary to 
support the next call mode. The network shall stop sending Bm-channel information and stop interpreting received Bm- 
channel information according to the old call mode at the latest when it changes the channel configuration. 

Upon receipt of the MODIFY message, the destination side shall check to ensure that the requested call mode can still 
be supported and if so, it shall initiate the reservation of any resources necessary to support the next call mode; start 
T324 (mobile station side only) if the in-call modification procedure is triggered as a result of a service change from 
speech to UDI/RDI multimedia modes; and enter the "mobile originating modify" (network side) or "mobile terminating 
modify" state (mobile station side). 

5.3.4.3.2 Successful completion of in-call modification 

If the destination network/mobile station receives a MODIFY message with a new mode which is already the actual one 
of the call the network/mobile station shall remain in the "active" state; send a MODIFY COMPLETE message with the 
actual mode; and shall not initiate anything else. 
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If the requested mode is speech and if during call establishment the network received a Supported Codec List IE, the 
network shall use this list to select the codec for UTRAN. If no Supported Codec List information element is received, 
then for UTRAN the network shall select the default UMTS speech codec according to subclause 5.2.1.1 1. 

Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in 
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer 
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1. 

If the Supported Codec List IE is received, then the network shall indicate the codec selected for lu mode to the mobile 
station via RANAP and RRC protocol in the NAS Synchronisation Indicator IE (see subclause 5.2.1.11). 

If the in-call modification was originated by the mobile station, the mobile station and the network shall proceed as 
follows: 

If the requested mode is not the actual one and can be supported by the network it shall change the channel 
configuration, if required, and step on to any internal resources necessary to support the next call mode. If the 
requested mode is a data or facsimile mode, it shall also perform the appropriate means to take the direction of 
the data call into account. After successful change of the channel configuration it shall start sending user 
information according to the next call mode and start interpreting received user channel information according to 
the next call mode; send a MODIFY COMPLETE message with the new call mode included and enter the 
"active" state (network side). If the MODIFY message had contained a reverse call setup direction IE, the same 
IE shall be included in the MODIFY COMPLETE message. 

Upon receipt of the MODIFY COMPLETE message the mobile station shall: initiate the alternation to those 
resources necessary to support the next call mode; stop timer T323; and enter the "active" state (mobile station 
side). 

If the in-call modification was originated by the network, the mobile station and the network shall proceed as follows: 

If the requested mode is not the actual one and can be supported by the mobile station it shall reserve any 
internal resources necessary to support the next call mode. 

NOTE: For a change from speech to a different call mode, user interaction may be required, before the mobile 
decides that the requested mode can be supported. 

If the requested mode is a data or facsimile mode, it shall also perform the appropriate means to take the 
direction of the data call into account. The mobile station shall send a MODIFY COMPLETE message with the 
new call mode included, stop timer T324 and enter the "active" state (mobile station side). If the MODIFY 
message had contained a reverse call setup direction IE, the same IE shall be included in the MODIFY 
COMPLETE message. If the old call mode is speech, the mobile station shall continue sending Bm-channel 
information and interpreting received Bm-channel information for speech until the network modifies its channel 
configuration. 

After receipt of the MODIFY COMPLETE message the network shall: reserve any internal resources necessary 
to support the next call mode, stop sending Bm-channel information, and stop interpreting received Bm-channel 
information according to the old call mode, unless these actions were already performed earlier. Furthermore, the 
network shall change the channel configuration, if required; after successful change of the channel configuration 
initiate the alternation to those resources necessary to support the next call mode; stop timer T323; and enter the 
"active" state (network side). 

The mobile station shall start sending user information according to the next call mode and start interpreting 
received user channel information according to the next call mode as soon as a suitable channel for the new 
mode is available. 

In both cases: 

For an alternate speech/facsimile group 3 service (refer to subclause 5.3.4) the old resources may still be kept 
reserved. 

The reaction of the originating side if it had included a reverse call setup direction IE in the MODIFY message, 
but the destination side did not include the IE in the MODIFY COMPLETE message is implementation 
dependent. 
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5.3.4.3.3 Change of the channel configuration 

In case the requested bearer capability cannot be supported by the current channel configuration the network shall 
initiate the assignment procedure and change the channel configuration accordingly. 

5.3.4.3.4 Failure of in-call modification 

5.3.4.3.4.1 Network rejection of in-call modification 

If the network cannot support the change to the requested call mode or if the change of the channel configuration fails 
the network shall: release the resources which had been reserved for the alternation: send a MODIFY REJECT message 
with the old bearer capability and with cause # 58 "bearer capability not presently available" to the initiating mobile 
station; and enter the "active" state. If the change of the channel configuration fails, the network shall return to the 
internal resources required for the old call mode. 

Upon receipt of the MODIFY REJECT message with the old bearer capability the initiating mobile station shall: stop 
timer T323; release any resources which had been reserved for the alternation; resume sending user channel information 
according to the present call mode; resume interpreting received user channel information according to the present call 
mode; and enter the "active" state. 

5.3.4.3.4.2 Mobile station rejection of in-call modification 

If the mobile station cannot support the change to the requested call mode, the mobile station shall: stop timer T324; 
release any resources which had been reserved for the alternation; send a MODIFY REJECT message with the old 
bearer capability and cause # 58 "bearer capability not presently available", and enter the "active" state. 

Upon receipt of the MODIFY REJECT message the network shall: stop timer T323, release any resources which had 
been reserved for the alternation. 

5.3.4.3.4.3 Time-out recovery 

Upon expiration of T323 in either the mobile station or the network the procedures for call clearing shall be initiated 
(see subclause 5.4) with cause #102 "recovery on timer expiry". 

Upon expiration of T324 the mobile station shall: release any resources which had been reserved for the alternation; 
send a MODIFY REJECT message with the old bearer capability and cause #58 "bearer capability not presently 
available"; and enter the "active" state. 

5.3.4.4 Abnormal procedures 

If a MODIFY, MODIFY COMPLETE or MODIFY REJECT message is received in the "disconnect indication", 
"disconnect request" (mobile station side only) or "release request" state then the received message shall be discarded 
and no action shall be taken. 

If a MODIFY COMPLETE message indicating a call mode which does not correspond to the requested one is received 
or if a MODIFY REJECT message indicating a call mode which does not correspond to the actual one is received then 
the received message shall be discarded and no action shall be taken. 

If a MODIFY message indicating a call mode which does not belong to those negotiated and agreed during the 
establishment phase of the call, is received, then a MODIFY REJECT message with the actual call mode and with cause 
# 57 "bearer capability not authorized" shall be sent back. 
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Figure 5.10b/3GPP TS 24.008 In-call modification sequence initiated by network 

5.3.5 User initiated service level up- and downgrading (A/Gb mode and 
GERAN lu mode only) 

The user initiated service level up- and downgrading is applicable for non-transparent multislot data services, only. By 
means of this procedure the user can request a change of the "maximum number of traffic channels" and/or "wanted air 
interface user rate" parameters, to be assigned by the network. 

5.3.5.1 Initiation of service level up- and downgrading 

The procedure is initiated by the mobile station in the "active" state of the call. It shall: 

send a MODIFY message including the wanted value of the "maximum number of traffic channels" and/or the 
"wanted air interface user rate" parameters; 

not change any of the other, possibly negotiated, parameters of the bearer capability information element; 

start timer T323; and 

enter the "mobile originating modify" state. 

Any internal resources necessary to support the next service parameters shall be reserved. If a dual service was 
negotiated at call setup, the mobile station shall initiate the service level up- or down-grading only during the data phase 
of the dual service. 

Upon receipt of the MODIFY message, the network shall check if the indicated maximum number of traffic channels 
can be supported and enter the "mobile originating modify" state. 

5.3.5.2 Successful completion of service level up- and downgrading 

The network may upon reception of the MODIFY message initiate a change of the channel configuration assigned to 
the mobile station. 

As a response to the MODIFY message the network sends a MODIFY COMPLETE message including the bearer 
capability negotiated at call setup and enters the "active" state. 
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Upon receipt of the MODIFY COMPLETE message the mobile station shall stop timer T323 and enter the "active" 
state. 

5.3.5.3 Rejection of service level up- and downgrading 

If a change of bearer service is requested together with a change of the "maximum number of traffic channels" and/or 
the "wanted air interface user rate", or if the current used service is not a data service where up- and downgrading is 
applicable, or if the receiver chooses not to grant the request, the network shall; 

send a MODIFY REJECT message with bearer capability negotiated at call setup and with cause #58 "bearer 
capability not presently available"; 

enter the "active" state. 

Upon receipt of the MODIFY REJECT message with the bearer capability negotiated at call setup, the mobile station 
shall: stop timer T323 and enter the "active" state. 

5.3.5.4 Time-out recovery 

Upon expiration of T323 in the mobile station the procedures for call clearing shall be initiated with cause #102 
"recovery on timer expiry". 

5.3.6 Support of multimedia calls 

5.3.6.1 Service description 

The 3GPP circuit-switched multimedia call is based on the 3G-324M (see 3GPP TS 26. 1 1 1 [80]), which is a 3GPP- 
variant of the ITU-T H.324 Recommendation. CS Multimedia telephony is a Bearer Service, which utilizes the 
Synchronous Transparent Data service (BS30) [3]. 

At the multimedia call setup the required call type, 3G-324M, is indicated, for the network to be able to invoke 
appropriate interworking functionality. In the peer end the H.324 information is used to invoke the terminal application. 
In addition to H.324 indication the terminal must select Information Transfer Capability (ITC) for the multimedia call. 
The 'correct' ITC depends on the peer end and the transporting networks; an all-ISDN call is a UDI/RDI call, and a call, 
which involves PSTN, is an analog "3.1 kHz audio" call. 

For the case when the setup of a multimedia call is not successful, fallback to speech is specified. 

Users may also request a service change between UDI/RDI multimedia and speech modes during a call (see 3GPP TS 
23.172 [97]). 

5.3.6.2 Call establishment 

For both mobile originating and mobile terminating calls, the normal call establishment procedures apply, with the 
exceptions specified in the following subclauses. 

For further description of the function of MSC/IWF in the following clauses, see 3GPP TS 29.007 [38]. 

5.3.6.2.1 Mobile originated multimedia call establishment 

At call setup the required call type, 3G-324M, is indicated by the originating MS in the SETUP message, with the 
bearer capability IE parameter Other Rate Adaptation set to "H.223 and H.245". 

For analogue multimedia, the support of a fallback to speech is requested by including two bearer capability lEs, 
multimedia first and speech as the second EC in the SETUP message. The MS shall indicate fallback to speech by these 
two BC lEs and the associated Repeat Indicator set to "support of fallback". 

For UDI/RDI multimedia, the support of a fallback and service change is requested by including two bearer capability 
IBs, with the first BC as the preferred service in the SETUP message. The MS shall indicate service change and fallback 
by these two BC lEs and the associated Repeat Indicator set to "support of service change and fallback". 
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If the bearer capability IE is received from the MS either in A/Gb or GERAN lu mode and indicates no A/Gb mode 
support for the requested bearer service, the network shall consider it as a request to perform an inter-system handover 
to UTRAN lu mode, as described in 3GPP TS 23.009 [114] subclause 14.2. 

The bearer compatibility checking in the network is according to subclause 5.3.4.2.1. 

If the MS requested for an analogue multimedia call with fallback to speech, or for a UDI/RDI multimedia call with 
fallback and service change, and the network accepts the call, the network has the following options for the inclusion of 
bearer capability lEs in the CALL PROCEEDING message: 

if the network accepts the requested analogue multimedia call and supports fallback to speech, both multimedia 
and speech bearer capability IBs shall be included; 

if the network accepts the requested UDI/RDI multimedia call and supports fallback and service change, both 
multimedia and speech bearer capability IBs shall be included. The order of the bearer capability lEs determines 
the preferred service, and the network may reverse the order of these lEs (see 3GPP TS 23.172 [97], 
subclause 4.2.1); 

if the network accepts a multimedia (only) call, a multimedia bearer capability IB shall be included; 

if the network accepts a speech (only) call, a speech bearer capability IB shall be included; 

for a UDI/RDI multimedia call, if the network accepts the requested speech call and supports service change, 
both multimedia and speech bearer capability IBs shall be included. The order of the bearer capability lEs 
determines the preferred service, and the network may reverse the order of these lEs (see 3GPP TS 23.172 [97], 
subclause 4.2.1); 

if the network received a UDI/RDI multimedia bearer capability IE with FNUR equal to 32kbit/s and a speech 
bearer capability IE in the SETUP message, the network shall not release the call, but shall reply with one 
bearer capability IE only, as specified in 3GPP TS 23.172 [97]. 

NOTE: Service change and fallback for UDI/RDI multimedia calls is not supported with Fixed Network User 
Rate set to 32 kbit/s (see 3GPP TS 23.172 [97]). 

If the MS requested for a multimedia call only, and the network accepts the call, the network shall always include a 
single multimedia bearer capability IB in the CALL PROCEEDING message. 

The originating user shall determine (possibly by pre -configuration of the terminal) whether a digital connection is 
required or if the call will be an analog modem call. If the call is expected to be digital the multimedia bearer capability 
IE parameter ITC is set to UDI/RDI. In an analog call the multimedia bearer capability IE parameter ITC is set to 
"3,1 kHz audio ex PLMN". Additionally required modem type is indicated (Other Modem Type = V.34). 

5.3.6.2.1.1 Fallback 

If the network, during the setup of an H.324-call, detects that the transit network or the called end does not support an 
H.324 call {e.g. because of a failure in the modem handshaking in case of an analogue multimedia call), then the 
network initiates the in-call modification procedure (see subclause 5.3.4.3) towards the MS to modify the call mode to 
speech, if the MS had included a speech bearer capability IB in the SETUP message. 

In case of a UDI/RDI multimedia call with service change and fallback, if the network detects that the called end does 
not support speech, then it initiates an in-call modification procedure towards the MS to modify the call mode to 
multimedia, if the first bearer capability IB was for a speech call. 

5.3.6.2.2 Mobile terminating multimedia call 

At call setup the required call type, 3G-324M, is indicated by the network in the SETUP message, with the bearer 
capability /£ parameter. Other Rate Adaptation set to 'H.223 and H.245'. ITC is either '3,1 kHz audio ex PLMN' or 
'UDI/RDI'. 

For analogue multimedia, if the network supports fallback to speech and the subscriber has subscription to speech, two 
bearer capability lEs, multimedia first and speech as the second BC are included in the SETUP message. The network 
shall indicate fallback to speech by these two BC lEs and the associated Repeat Indicator set to "support of fallback". 
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For UDI/RDI multimedia, if the network supports fallback and service change, and the subscriber has subscription to 
speech, two bearer capability lEs, with the first BC as the preferred service are included in the SETUP message. The 
network shall indicate service change and fallback by these two BC lEs and the associated Repeat Indicator set to 
"service change and fallback". 

If the bearer capability IE is received from the MS either in A/Gb or GERAN lu mode and indicates no A/Gb mode 
support for the requested bearer service, the network shall consider it as a request to perform an inter-system handover 
to UTRAN lu mode, as described in 3GPP TS 23.009 [114] subclause 14.2. 

The bearer capability IE(s) may (in the case of the single numbering scheme) be missing from the SETUP message. 

The bearer compatibility checking in the MS is according to subclause 5.3.4.2.2. 

The MS shall indicate the supported call type(s) in the CALL CONFIRMED message, which is the acknowledgement 
to SETUP. If the network offered an analogue multimedia call with fallback to speech, or a UDI/RDI multimedia call 
with fallback and service change, the MS has the following options for the inclusion of bearer capability lEs in the 
CALL CONFIRMED message: 

if the MS/user accepts the offered analogue multimedia call and supports fallback to speech, both multimedia 
and speech bearer capability lEs shall be included; 

if the MS/user accepts the offered UDI/RDI multimedia call, and supports fallback and service change, both 
multimedia and speech bearer capability lEs shall be included. The order of the BC lEs determines the preferred 
service, and the MS/user may reverse the order of these lEs; 

if the MS/user accepts the offered multimedia call, but does not support fallback or service change, only a 
multimedia bearer capability IE shall be included; 

if the MS/user wishes a speech (only) call a speech bearer capability IE is included; 

for a UDI/RDI multimedia call, if the MS/user accepts the offered speech call and supports service change, both 
speech and multimedia bearer capability lEs shall be included. The order of the BC lEs determines the preferred 
service, and the MS/user may reverse the order of these lEs. 

If the network offered a multimedia call only, and the MS/user accepts the call, the MS shall always include a single 
multimedia bearer capability IE in the CALL CONFIRMED message. 

If the SETUP contained no bearer capability IE the network shall perform compatibility checking of the CALL 
CONFIRMED message in the same way as the compatibility checking of the SETUP message in the mobile originating 
call case, described in subclause 5.3.6.2.1. 

5.3.6.2.2.1 Fallback to speech 

If modem handshaking fails (in a modem call), the call mode will be modified to speech if a speech bearer capability IE 
was included. The modem signalling is inband, so the call must have reached the active state, when these conclusions 
about the presence of modems can be done. The call modifications are realized through the in-call modification 
procedure, by which the network requests the MS to modify the call mode (see subclause 5.3.4.3). 

NOTE: Fallback from digital (UDI) H.324-call to speech after call setup is not a valid case at the terminating 
side. 

5.3.6.3 In-call modification in the "active" state 

The in-call modification procedure as described in subclause 5.3.4.3 shall be used to: 

- trigger a service change between speech and UDI/RDI multimedia modes, when service change has been agreed 
at call setup; 

trigger a network-initiated service upgrade from speech to UDI/RDI multimedia modes (see 
3GPP TS 23.172 [97]). The network shall initiate this procedure only if the mobile station indicated support of 
the enhanced network-initiated in-call modification procedure in the Call Control Capabilities IE at call 
establishment. In this case, the MODIFY message shall include the Network-initiated Service Upgrade indicator 
IE; or 
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modify the multimedia bearer capability for an analogue multimedia call (restricted to the network initiated in- 
call modification only). In this case, the network shall send a MODIFY message including the new Bearer 
Capability to be changed to. The following bearer capability parameters can be modified with the procedure (see 
3GPP TS 29.007 [38]): 

Fixed Network User Rate (analogue multimedia calls only). 

5.3.6.3.1 Void 

5.3.6.3.2 Void 

5.3.6.3.3 Void 

5.3.6.3.3.1 Void 

5.3.6.3.3.2 Void 

5.3.6.4 Multimedia CAT during the alerting phase of a mobile originated call 

A mobile station supporting multimedia CAT during the alerting phase of a mobile originated multimedia call 
establishment shall indicate support of this capability to the network in the Call Control Capabilities information 
element in the SETUP message. 

The network may generate a multimedia CAT to such a mobile station before it has reached the "active" state of a call. 
To do so, the network shall through connect the traffic channel towards the source of the multimedia CAT and send a 
progress indicator IE indicating user attachment with progress description #9 "In-band multimedia CAT available" in 
either an ALERTING message or a PROGRESS message that is sent to the mobile station during call establishment. 

On reception of an ALERTING or a PROGRESS message the mobile station shall proceed as specified elsewhere in 
clause 5; if the progress indicator IE indicated user attachment with progress description #9 "In-band multimedia CAT 
available", the mobile station shall: 

attach the user connection for multimedia as soon as an appropriate channel in multimedia mode is available; and 

set up an H.324 call. 

It is up to the network to ensure that no undesired end-to-end through connection with the called party takes place 
during the establishment of a mobile terminated call. 

The mobile station shall not abort the call if an error or H.324 call clearing occurs during the setup or the lifetime of the 
H.324 call during the alerting phase; the call control entity of the calling mobile station shall remain in its current state. 

Upon reception of a new request from the network to attach the user connection with progress description #9 "In-band 
multimedia CAT available", the mobile station shall release any on-going H.324 call, and set up a new H.324 call. 

NOTE: The network can request the mobile station to restart a new H.324 call during the alerting phase of the call 
e.g. during call forwarding scenarios to transmit to the calling party the multimedia CAT of the 
forwarded-to party. 

The network may initiate the in-call modification procedure (see subclause 5.3.4.3) towards the MS in the "call 
delivered" state to modify the call mode to speech, if service change has been agreed at call setup. 

Upon receiving an indication that the call has been accepted, the call control entity of the network shall send a 
CONNECT message to its peer entity at the calling mobile station; start timer T313 and enter the "connect indication" 
state. This message indicates to the call control entity of the calling mobile station that a connection has been 
established through the network. 

On reception of a CONNECT message, the mobile station shall proceed as specified elsewhere in clause 5; the mobile 
station shall release any on-going H.324 call and set up a new H.324 call towards the called party. 
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Mobile stations supporting multimedia CAT during the alerting phase of a mobile originated multimedia call 
establishment should also support the Media Oriented Negotiation Acceleration procedures specified in ITU- 
T H.324 annex K (see [117] and [118]). 

5.3.6.5 DTMF transmission during a multimedia call 

A mobile station supporting multimedia CAT during the alerting phase of a mobile originated multimedia call 
establishment should support transmission of DTMFs during a H.324 call using the H.245 Userlnputlndication message 
(see ITU-T H.245 [119]) if it has attached the user connection for multimedia and an appropriate channel is available. 

NOTE: DTMF can be used to convey to the network the end user request to stop or copy an on-going multimedia 
CAT. 

5.4 Call clearing 

5.4.1 Terminology 

The following terms are used in the present document in the description of clearing procedures: 

A traffic channel (see 3GPP TS 44.003 [16]) is "connected" when the channel is part of a circuit-switched 
connection established according to the present document. 

A traffic channel is "disconnected" when the channel is no longer part of a circuit-switched connection, but is not 
yet available for use in a new connection. 

5.4.2 Exception conditions 

Under normal conditions, the call control entity of the mobile station or of the network initiates call clearing by sending 
a DISCONNECT message to its peer entity; then both entities follow the procedures defined in subclauses 5.4.3 and 
5.4.4 respectively. 

As an exception to the above rule, the call control entity of the mobile station or of the network, in response to a SETUP 
or START CC or CC-ESTABLISHMENT CC-ESTABLISHMENT CONFIRMED or RECALL message, can reject a 
call by stopping all running call control timers, responding with a RELEASE COMPLETE message, releasing the MM 
connection, and returning to the "null" state, provided no other response has previously been sent. 

As a further exception, the call control entity of the network may initiate call clearing by stopping all running call 
control timers, sending a RELEASE message, starting timer T308, and entering the "release request" state. 

NOTE: This way to initiate call clearing by sending a RELEASE message should not be used by the network: 

if in-band tones/announcements are provided and the network decides to use the procedure described 
in subclause 5.4.4.1.1.1 or 5.4.4.2.1; 

if the network wants to have the opportunity to respond to information sent by the mobile station 
during call clearing, e.g. when the network indicates that "CCBS activation is possible". 

A call control entity shall accept an incoming RELEASE COMPLETE message used to initiate the call clearing even 
though the cause information element is not included. 

A control entity shall accept an incoming RELEASE message used to initiate the call clearing even though the cause 
information element is not included. 

Furthermore, a call control entity shall regard an incoming RELEASE COMPLETE message as consistent with any of 
its states; a call control entity shall regard an incoming RELEASE message as consistent with any of its states except 
the null state: a call control entity of the mobile station shall regard an incoming DISCONNECT message as consistent 
with any of its call control states except the "null" state, the "release request" state, and the "disconnect indication" state; 
a call control entity of the network shall regard an incoming DISCONNECT message as consistent with any of its call 
control states except the "null" state and the "release request" state. 

NOTE: This allows the introduction of shorter call clearing procedures in the future. 
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5.4.3 Clearing initiated by tine mobile station 

5.4.3.1 initiation of call clearing 

Apart from the exceptions identified in subclause 5.4.2, the call control entity of the mobile station shall initiate clearing 
by: stopping all running call control timers, sending a DISCONNECT message; starting timer T305; and entering the 
"disconnect request" state. 

5.4.3.2 Receipt of a DISCONNECT message from the mobile station. 

The call control entity in the network in any state except the "null" state and the "release request" state shall, upon 
receipt of a DISCONNECT message: 

Stop all running call control timers; 

initiate procedures to clear the network connection and the call to the remote user; 

send a RELEASE message to its peer entity; 

start timer T308; and 

enter the "release request" state. 

NOTE: The RELEASE message has only local significance and does not imply an acknowledgement of clearing 
from the remote user. 

5.4.3.3 Receipt of a RELEASE message from the network 

The call control entity of the mobile station in any state except the "null" state and the "release request" state, shall, 
upon receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE message; 
release the MM connection; and return to the "null" state. 

5.4.3.4 Receipt of a RELEASE COMPLETE message from the mobile station 

A call control entity of the network in any call control state shall, upon receipt of a RELEASE COMPLETE message 
from its peer entity in the mobile station: stop all running call control timers; release the MM connection; and return to 
the "null" state. 

5.4.3.5 Abnormal cases 

The call control entity of the mobile station in the "disconnect request" state, shall upon expiry of timer T305: send a 
RELEASE message to the network with the cause number originally contained in the DISCONNECT message and 
optionally, a second cause information element with cause #102 "recovery on timer expiry", start timer T308, and enter 
the "release request" state. 

The call control entity of the network in the "release request" state, shall, at first expiry of timer T308, retransmit the 
RELEASE message, start timer T308, and stay in the "release request" state. At second expiry of timer T308, the call 
control entity of the network shall: release the MM connection; and return to the "null" state. 

5.4.4 Clearing initiated by the network 

Apart from the exception conditions identified in subclause 5.4.2, the call control entity of the network shall initiate 
clearing by: sending a DISCONNECT message; and entering the "disconnect indication" state. The DISCONNECT 
message is a local invitation to clear the call. 

NOTE: When the network initiates clearing by sending a RELEASE message, the procedures described in 
subclauses 5.4.3., 5.4.3.4 and 5.4.3.5 are followed. 

A mobile station that does not support the "Prolonged Clearing Procedure" shall comply with the requirements of 
subclause 5.4.4.1 and shall ignore subclause 5.4.4.2. A mobile station that supports the "Prolonged Clearing Procedure" 
shall comply with the requirements of subclauses 5.4.4.2 and shall ignore subclause 5.4.4.1. 
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5.4.4.1 Clearing initiated by the network: mobile does not support "Prolonged 

Clearing Procedure" 

Sublause 5.4.4.1 only applies to mobile stations that do not support the "Prolonged Clearing Procedure" option. 

5.4.4.1 .1 Clearing when tones/announcements provided 

When in-band tones/announcements are provided (see subclause 5.5.1), the call control entity of the network may 
initiate clearing by sending a DISCONNECT message containing progress indicator #8 "in-band information or 
appropriate pattern now available", starting timer T306, and entering the "disconnect indication" state. 

5.4.4.1 .1 .1 Receipt of a DISCONNECT message with progress indicator #8 from tine network 

The call control entity of the MS in any state except the "null" state, the "disconnect indication" state, and the "release 
request" state, shall, upon receipt of a DISCONNECT message with progress indicator #8: 

i) if an appropriate speech traffic channel is not connected, continue clearing as defined in subclause 5.4.4.1.2.1 
without connecting to the in-band tone/announcement; 

ii) if an appropriate speech traffic channel is connected, attach the user connection for speech if it is not yet attached 
and enter the "disconnect indication" state. In that state, if upper layers request the clearing of the call, the call 
control entity of the MS shall proceed as defined in subclause 5.4.4.1.2.1. 

5.4.4.1.1.2 Expiry of timer T306 

The call control entity of the network, having entered the "disconnect indication" state after sending a disconnect 
message with the progress indicator #8, shall, upon expiry of timer T306, continue clearing by sending a RELEASE 
message with the cause number originally contained in the DISCONNECT message; starting timer T308; and entering 
the "release request" state. 

5.4.4.1 .2 Clearing when tones/announcements not provided 

When in-band tones and announcements are not provided, the call control entity of the network shall initiate call 
clearing by stopping all running call control timers, sending a DISCONNECT message without progress indicator, 
starting timer T305 and entering the "disconnect indication" state. 

5.4.4.1 .2.1 Receipt of a DISCONNECT message witlnout progress indicator or with progress 
indicator different from #8 from the network 

The call control entity of the mobile station in any state except the "null" state, the "disconnect indication" state, and the 
"release request" state, shall, upon the receipt of a DISCONNECT message without progress indicator information 
element or with progress indicator different from #8; 

stop all running call control timers; 

send a RELEASE message; 

start timer T308; and 

enter the "release request" state. 

5.4.4.1 .2.2 Receipt of a RELEASE message from the mobile station 

The call control entity of the network in any state except the "null" state and the "release request" state, shall, upon 
receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE message; release 
the MM connection; and return to the "null" state. 
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5.4.4.1.2.3 Abnormal cases 

The call control entity of the network, having entered the "disconnect indication" state after sending a DISCONNECT 
message without progress indicator or with progress indicator different from #8, shall upon expiry of timer T305: send a 
RELEASE message to the mobile station with the cause number originally contained in the DISCONNECT message; 
start timer T308; and enter the "release request" state. In addition to the original clearing cause, the RELEASE message 
may contain a second cause information element with cause #102 "recovery on timer expiry". 

5.4.4.1 .3 Completion of clearing 

A call control entity of the mobile station in any call control state shall, upon receipt of a RELEASE COMPLETE 
message from its peer entity in the network: stop all running call control timers; release the MM connection; and return 
to the "null" state. 

5.4.4.1 .3.1 Abnormal cases 

The call control entity of the mobile station in the "release request" state shall at first expiry of timer T308 retransmit 
the RELEASE message and restart timer T308. At second expiry of timer T308, the call control entity of the mobile 
station shall: release the MM connection; and return to the "null" state. 

5.4.4.2 Clearing initiated by the network: mobile supports "Prolonged Clearing 

Procedure" 

Sublause 5.4.4.2 only applies to mobile stations that support the "Prolonged Clearing Procedure" option. 

5.4.4.2.1 Clearing when tones/announcements provided and the network does not indicate 

that "CCBS activation is possible" 

When in-band tones/announcements are provided (see subclause 5.5.1) and CCBS is not applicable, the call control 
entity of the network may initiate clearing by sending a DISCONNECT message containing progress indicator #8 "in- 
band information or appropriate pattern now available", either not containing an Allowed Actions IE or containing an 
Allowed Actions IE indicating "CCBS activation is not possible", starting timer T306, and entering the "disconnect 
indication" state. 

5.4.4.2.1 .1 Receipt of a DISCONNECT message 

The call control entity of the MS in any state except the "null" state, the "disconnect indication" state, and the "release 
request" state, shall, upon receipt of a DISCONNECT message with progress indicator #8 and, either not containing an 
Allowed Actions IE or containing an Allowed Actions IE indicating "CCBS activation is not possible": 

i) if an appropriate speech traffic channel is not connected, 

stop all running call control timers; 

send a RELEASE message; 

start timer T308; 

enter the "release request" state; and 

not connect to the in-band tone/announcement. 

ii) if an appropriate speech traffic channel is connected, attach the user connection for speech if it is not yet attached 
and enter the "disconnect indication" state. In that state, if upper layers request the clearing of the call, the call 
control entity of the MS shall: 

stop all running call control timers; 

send a RELEASE message; 

start timer T308; and 

enter the "release request" state. 
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5.4.4.2.1.2 Expiry of timer T306 

The call control entity of the network, having entered the "disconnect indication, shall, upon expiry of timer T306, 
continue clearing by sending a RELEASE message with the cause number originally contained in the DISCONNECT 
message; starting timer T308; and entering the "release request" state. 

5.4.4.2.2 Clearing when the network indicates that "CCBS activation is possible" 

When Activation of CCBS is possible, the call control entity of the network may initiate clearing by sending a 
DISCONNECT message containing the Allowed Actions IE with an indication that "Activation of CCBS is possible" 
and starting T338. Optionally, progress indicator #8 "in-band information or appropriate pattern now available" may 
also be contained in the DISCONNECT message (in which case, T338 shall not be greater than T306). 

5.4.4.2.2.1 Receipt of a DISCONNECT 

Relative to the current state the following procedures apply: 

The call control entity of the MS in the "null" state, the "disconnect indication" state and the "release request" 
state, shall, upon receipt of a DISCONNECT message react as described in clause 8. 

The call control entity of the MS in the "disconnect request" state, shall, upon receipt of a DISCONNECT 
message: 

stop all running call control timers; 

send a RELEASE message; 

start timer T308; and 

enter the "release request" state. 

The call control entity of the MS in any other states, shall, upon receipt of a DISCONNECT message with an 
Allowed Actions IE indicating "Activation of CCBS is possible" pass the "Activation of CCBS is possible" 
indication to the upper layer, enter the "disconnect indication" state, stop all running call control timers and await 
a response from the upper layers. 

If the DISCONNECT message contained the progress indicator #8 "in-band information or appropriate pattern now 
available" and an appropriate speech traffic channel is connected, then the MS shall attach the user connection for 
speech if it is not yet attached. If the DISCONNECT message did not contain the progress indicator #8 "in-band 
information or appropriate pattern now available" any connected speech traffic channel shall be disconnected. 

Response from the upper layers: 

i) If the upper layers request the clearing of the call, the call control entity of the MS shall: 

stop all running call control timers; 

send a RELEASE message; 

start timer T308; and 

enter the "release request" state, 
ii) If the upper layers request that the "CCBS activation is to be attempted" then the MS shall 

send a RELEASE message containing a Facility IE including an 

Invoke=CCBSRequest to the network; 

stop all running call control timers; 

start timer T308; and 

enter the "release request" state. 
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If an appropriate speech traffic channel is connected, transmission of this RELEASE message shall not cause it 
to be disconnected. 

5.4.4.2.2.2 Expiry of timer T338 

The call control entity of the network, having entered the "disconnect indication" state after sending a DISCONNECT 
message with an Allowed Actions IE indicating "Activation of CCBS is possible" shall, upon expiry of timer T338, 
continue clearing by sending a RELEASE message with the cause number originally contained in the DISCONNECT 
message; starting timer T308; and entering the "release request" state. 

5.4.4.2.3 Clearing when tones/announcements are not provided and the network does not 
indicate that "CCBS activation is possible" 

When in-band tones and announcements are not provided, and, the network does not wish to indicate in the Allowed 
Actions IE that "CCBS is possible", the call control entity of the network shall initiate call clearing by stopping all 
running call control timers, sending a DISCONNECT message without progress indicator, either without the Allowed 
Actions IE or with the Allowed Actions IE indicating that "CCBS is not possible", starting timer T305 and entering the 
"disconnect indication" state. 

5.4.4.2.3.1 Receipt of a DISCONNECT message 

The call control entity of the mobile station in any state except the "null" state, the "disconnect indication" state, and the 
"release request" state, shall, upon the receipt of a DISCONNECT message either without progress indicator 
information element or with progress indicator different from #8, and, either without the Allowed Actions IE or with the 
Allowed Actions IE indicating that "CCBS is not possible": 

stop all running call control timers; 

send a RELEASE message; 

start timer T308; and 

enter the "release request" state. 

5.4.4.2.3.2 Abnormal cases 

The call control entity of the network, having entered the "disconnect indication", shall upon expiry of timer T305: send 
a RELEASE message to the mobile station with the cause number originally contained in the DISCONNECT message; 
start timer T308; and enter the "release request" state. 

5.4.4.2.4 Receipt of a RELEASE message from the mobile station 

5.4.4.2.4.1 Release, CCBS not requested 

For a network that does not support the "CCBS activation" option: 

The call control entity of the network in any state except the "null" state and the "release request" state, shall, 
upon receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE 
message; release the MM connection; and return to the "null" state. 

For a network that does support the "CCBS activation" option: 

The call control entity of the network in any state except the "null" state and the "release request" state, shall, 
upon receipt of a RELEASE message without a Facility IE including an Invoke=CCBSRequest: stop all running 
call control timers; send a RELEASE COMPLETE message; release the MM connection; and return to the "null" 

state. 
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5.4.4.2.4.2 Release, CCBS Requested 

For a network that does not support the "CCBS activation" option: 

The call control entity of the network in any state except the "null" state and the "release request" state, shall, 
upon receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE 
message; release the MM connection; and return to the "null" state. 

For a network that does support the "CCBS activation" option: 

The call control entity of the network in any state except the "null" state and the "release request" state, shall, 
upon receipt of a RELEASE message containing a Facility IE including an Invoke=CCBSRequest: stop all 
running call control timers; then attempt to activate the recall; then send a RELEASE COMPLETE message 
indicating the success or failure of the recall activation attempt; release the MM connection; and return to the 
"null" state. 

5.4.4.2.5 Completion of clearing 

A call control entity of the mobile station in any call control state shall, upon receipt of a RELEASE COMPLETE 
message from its peer entity in the network: stop all running call control timers; release the MM connection; and return 
to the "null" state. 

5.4.4.2.5.1 Abnormal cases 

The call control entity of the mobile station in the "release request" state shall at first expiry of timer T308 retransmit 
the RELEASE message and restart timer T308. At second expiry of timer T308, the call control entity of the mobile 
station shall: release the MM connection; and return to the "null" state. 

The retransmitted RELEASE message need not contain the Facility IE including an Invoke=CCBSRequest, even if the 
original RELEASE message did contain this IE.5.4.5Clear collision 

Clear collision occurs when both the mobile station and the network simultaneously transfer DISCONNECT messages 
specifying the same call. 

The behaviour of the network call control entity receiving a DISCONNECT message whilst in the "disconnect 
indication" state is specified in subclause 5.4.3. The behaviour of the MS call control entity receiving a DISCONNECT 
message whilst in the "disconnect request" state is defined in subclause 5.4.4. 

Clear collision can also occur when both sides simultaneously transfer RELEASE messages related to the same call. 
The entity receiving such a RELEASE message whilst within the "release request" state shall: stop timer T308; release 
the MM connection; and enter the "null" state (without sending a RELEASE COMPLETE message). 

5.5 Miscellaneous procedures 
5.5.1 In-band tones and announcements 

When the network wants to make the mobile station attach the user connection (e.g. in order to provide in-band 
tones/announcement) before the mobile station has reached the "active" state of a call, the network may include a 
progress indicator IE indicating user attachment in a suitable CC message: 

- Either it includes the IE in a SETUP, CALL PROCEEDING, ALERTING, or CONNECT message that is send 
during call establishment 

it sends a PROGRESS message containing the IE. 

A progress indicator IE indicates user attachment if it specifies a progress description in the set { 1 , 2, 3 } or in the set 
{6, 7, 8, ...,20}. 
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On reception of a SETUP, CALL PROCEEDING, ALERTING, CONNECT, or PROGRESS message the mobile 
station shall proceed as specified elsewhere in clause 5; if the progress indicator IE indicated user attachment and a 
speech mode traffic channel is appropriate for the call the mobile station shall in addition: attach the user connection for 
speech as soon as an appropriate channel in speech mode is available. (If a new order to attach the user connection is 
received before the attachment has been performed, the new order shall supersede the previous one.) 

Under certain conditions the MS will have to attach the user connection before the CONNECT message. It is up to the 
network to ensure that no undesired end-to-end through connection takes place during the establishment of a MT call. 

NOTE: This allows the use of progress indicator lEs independently from the channel modes appropriate for the 
call. 

The network may generate multimedia CAT to a mobile station supporting multimedia CAT during the alerting phase 
of a mobile originated multimedia call establishment as specified in subclause 5.3.6.4. 

5.5.2 Call collisions 

Call collisions as such cannot occur at the network. Any simultaneous mobile originating or mobile terminating calls 
are dealt with separately assigned and different transaction identifiers. 

5.5.3 Status procedures 

5.5.3.1 Status enquiry procedure 

Whenever a call control entity wishes to check the call state of its peer entity, it may initiate the status enquiry 
procedure. 

NOTE: This may, in particular, apply to procedural error conditions described in clause 8. 

A call control entity initiates the status enquiry procedure by sending the STATUS ENQUIRY message and starting 
timer T322. While timer T322 is running, the call control entity shall not send further STATUS ENQUIRY messages. 

Upon receipt of a STATUS ENQUIRY message, the receiver shall respond with a STATUS message, reporting the 
current call state and cause value #30 "response to STATUS ENQUIRY". Receipt of the STATUS ENQUIRY shall not 
result in a state change relating to any protocol and connection of the receiver. 

If a STATUS message is received that contains cause value #30 "response to status enquiry", timer T322 shall be 
stopped and further appropriate actions taken, based on the information in that STATUS message, relative to the current 
state of the receiver of the STATUS message. These further "appropriate actions" are implementation dependent. 
However, the actions prescribed in subclause 5.5.3.2 shall apply. 

If a clearing message is received while timer T322 is running, timer T322 shall be stopped, and call clearing shall 
continue. 

If timer T322 expires, the STATUS ENQUIRY message may be retransmitted maximally once. If T322 expires after 
the STATUS ENQUIRY has been transmitted the maximum number of times, clearing of the call shall be initiated with 
cause value #41, "temporary failure", in the first call clearing message. 

5.5.3.2 Reception of a STATUS message by a CC entity 

5.5.3.2.1 STATUS message with incompatible state 

On receipt of a STATUS message reporting an incompatible call control state, the receiving entity shall clear the call by 
sending a RELEASE COMPLETE message with cause # 101 "message not compatible with protocol state". The 
reported call control state is incompatible if the combination of call control states at the sender and receiver side cannot 
occur, do not match or cannot be aligned by actions of the receiver; the exact definition is implementation dependent. 

5.5.3.2.2 STATUS message with compatible state 

A STATUS message may be received indicating a compatible call state but containing one of the following causes: 
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# 95 "semantically incorrect message"; or 

# 96 "invalid mandatory information"; or 

# 97 "message type non-existent or not implemented"; or 

# 98 "message type not compatible with protocol state"; or 

# 99 "information element non-existent or not implemented"; or 

# 100 "conditional IE error". 

This indicates that the transmitter of the STATUS message was unable to accept some information sent by the recipient 
of the STATUS message. This allow the recipient to retransmit some or all of the information. Other actions are 
possible and are implementation dependent; they may include releasing the call. 

In the case the MS receives a STATUS message with the cause #100 due to the presence of a Repeat Indicator with the 
value "service change and fallback" in a SETUP message, it may then resend a new SETUP message with a single BC- 
lE (no Repeat Indicator is included). The actual behaviour is dependent on the implementation. 

In the case the network receives a STATUS message with the cause #100 due to the presence of a Repeat Indicator with 
the value "service change and fallback" in a SETUP message, it shall then resend a new SETUP message, with either 
the BC-IE of the preferred service or the speech BC-IE (fallback to speech) as the only BC (no Repeat Indicator is 
included). The preferred behaviour is decided by configuration. 

5.5.4 Call re-establishment, mobile station side 

This subclause describes the internal handling in the mobile station as far as call control is concerned. 

5.5.4.1 Indication from the mobility management sublayer 

When a MM connection is active, an indication may be given by the MM sublayer to the call control entity to announce 
that the current MM connection has been interrupted but might be re-established on request of call control. 

5.5.4.2 Reaction of call control 

Depending whether call re-establishment is allowed or not and on its actual state, call control shall decide to either 
request re-establishment or to release the MM connection. 

a) Re -establishment not required 

If the call is in the call establishment or call clearing phase, i.e. any state other than the "active" state or the 
"mobile originating modify" state, call control shall release the MM connection 

b) Re -establishment required 

If the call is in the "active" state or "mobile originating modify" state, the indication from MM that re- 
establishment is possible shall cause call control to request re -establishment from the MM connection, 
suspend any further message to be sent and await the completion of the re -establishment procedure. 

5.5.4.3 Completion of re-establishment 

Call Control is notified when the MM connection is re-established and shall then resume the transmission of possibly 
suspended messages and resume user data exchange when an appropriate channel is available. 

5.5.4.4 Unsuccessful outcome 

If the attempt to re-establish the connection was unsuccessful, the MM connection will be released and a release 
indication will be given to call control, see subclause 4.5.1.6. 
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5.5.5 Call re-establishment, network side 

This subclause describes the handling in the network as far as call control is concerned. 

5.5.5.1 State alignment 

After a successful call re -establishment it is a network responsibility to identify (e.g. by using the status enquiry 
procedure, if needed, and resolve, if possible, any call state or auxiliary state mismatch between the network and the 
mobile station. 

5.5.6 Progress 

At any time during the establishment or release of a call and during an active call the network may send a PROGRESS 
message to the mobile station. 

On receipt of a PROGRESS message during the establishment or release of a call the mobile station shall stop all call 
control timers related to that call. 

NOTE: If the PROGRESS has been received before the receipt of a CALL PROCEEDING message, the mobile 
station will not start timer T310 on receipt of a CALL PROCEEDING message, see subclause 5.2.1.1.3. 

H3 Network 

PROGRESS 
< 

Figure 5.11/3GPP TS 24.008 Progress 



5.5.7 DTMF protocol control procedure 



Dual Tone Multi Frequency (DTMF) is an inband one out of four plus one out of four signalling system primarily used 
from terminal instruments in telecommunication networks. The support of DTMF in the network is described in 
3GPPTS 23.014 [12]. 

The mobile station shall be capable of transmitting DTMF messages as specified in this subclause if and only if the 
mobile station has the user connection for speech attached and an appropriate channel is available. 

The transaction identifier used by the DTMF messages shall be that of the attached speech call. 

NOTE 1 : The present document means that DTMF messages can generally be sent in the active state of a call in 
speech transmission mode or when a traffic channel is available during setup or release and the progress 
indicator IE has been received. 

NOTE 2: Since the DTMF protocol messages are sent in a store and forward mode on the signalling channels the 
control of the device at the far end may be delayed dependent on the load or quality of the channels. 

NOTE 3: The procedures described in this paragraph support DTMF only in the direction mobile station to 
network. 

A mobile station supporting multimedia CAT during the alerting phase of a mobile originated multimedia call 
establishment should also be capable of transmitting DTMFs during a multimedia call as specified in subclause 5.3.6.5. 

5.5.7.1 Start DTMF request by the mobile station 

A user may cause a DTMF tone to be generated e.g. by depression of a key in the mobile station. The relevant action is 
interpreted by the mobile station as a requirement for a DTMF digit to be sent in a START DTMF message on an 
established FACCH. This message contains the value of the digit to be transmitted (0, 1, ..., 9, A, B, C, D, *, #). 

Only a single digit will be transferred in each START DTMF message. 

On sending a START DTMF message the MS shall start timer T336. 
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Where a previous START DTMF message has been sent, another START DTMF message shall only be sent by the MS 
following receipt of its STOP DTMF ACKNOWLEDGE message (see subclause 5.5.7.4) or a START DTMF REJECT 
message from the network (see subclause 5.5.7.2) or following the expiry of timers T336 and T337. 

If timer T336 expires, the MS shall terminate the ongoing DTMF procedure without any retransmissions, and is free to 
begin another DTMF procedure (e.g. another START DTMF message). 

5.5.7.2 Start DTMF response by the network 

Upon receiving the START DTMF message the network shall either: 

convert the received digit into a DTMF tone which is applied toward the remote user, or 

- send the DTMF digit as an out-of-band message (see 3GPP TS 23.205 [96]) 

and return a START DTMF ACKNOWLEDGE message to the mobile station. This acknowledgement may be used in 
the mobile station to generate an indication as a feedback for a successful transmission. 

If the network cannot accept the START DTMF message a START DTMF REJECT message will be sent to the mobile 
station. Upon receipt of a START DTMF ACK message or a START DTMF REJECT message, the MS shall stop timer 
T336. 

5.5.7.3 Stop DTMF request by the mobile station 

When the user indicates that the DTMF sending should cease e.g. by releasing the key the mobile station will send a 
STOP DTMF message to the network. 

On sending a STOP DTMF message the MS shall start timer T337. 

The MS shall only send a STOP DTMF message if a START DTMF ACKNOWLEDGE message has been received 
from the network (see subclause 5.5.7.2). 

If timer T337 expires, the MS shall terminate the ongoing DTMF procedure without any retransmissions, and is free to 
begin another DTMF procedure, (e.g. another START DTMF message). 

5.5.7.4 Stop DTMF response by the network 

Upon receiving the STOP DTMF message the network shall either: 

stop sending the DTMF tone if applied by the network, or 

initiate a suitable out-of-band message (see 3GPP TS 23.205 [96]) 

and return a STOP DTMF ACKNOWLEDGE message to the mobile station. Upon receipt of a STOP DTMF 
ACKNOWLEDGE message, the MS shall stop timer T337. 

5.5.7.5 Sequencing of subsequent start DTMF requests by the mobile station 

If the network is generating DTMF tones it shall ensure that the minimum length of tone and the minimum gap between 
two subsequent tones (according to ETSI ES 201 235-2 [12a]) is achieved. 

NOTE 1: In ETSI ES 201 235-2 [12a] the minimum duration of a DTMF tone is 65ms. 

NOTE 2: In ETSI ES 201 235-2 [12a] the minimum gap between DTMF tones is 65ms. 

There is no defined maximum length to the tone, which will normally cease when a STOP DTMF message is received 
from the MS. However, the operator may choose to put a pre-defined time limit on the duration of tones sent. 

The appropriate sequencing of DTMF control messages is shown in figures 5.8 and 5.9. 

NOTE 3: The network may implement the time limit option where the DTMF tone duration is controlled by the 
network irrespective of the receipt of a STOP DTMF message from the mobile station. 
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Figure 5.8/3GPP TS 24.008 Single DTIUIF transmission 
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Figure 5.9/3GPP TS 24.008 lUlultiple DTIVIF transmission 



Support for packet services 



This chapter contains the description of the procedures for the session management of GPRS point-to-point data 
services and MBMS point-to-point and point-to-muhipoint data services at the radio interface (Reference point Uu and 
Um). 

6.1 GPRS Session management 
6.1.1 General 

The main function of the session management (SM) is to support PDP context handhng of the user terminal. 
Furthermore, the SM supports the MBMS context handhng within the MS and the network, which allows the MS to 
receive data from a specific MBMS source. 

The SM comprises procedures for 

identified PDP context activation, deactivation and modification; and 

identified MBMS context activation and deactivation. 

SM procedures for identified access can only be performed if a GMM context has been established between the MS and 
the network. If no GMM context has been established, the MM sublayer has to initiate the establishment of a GMM 
context by use of the GMM procedures as described in chapter 4. After GMM context establishment, SM uses services 
offered by GMM (see 3GPP TS 24.007 [20]). Ongoing SM procedures are suspended during GMM procedure 
execution. 

The SM procedures for identified MBMS context activation and deactivation can only be performed, if in addition to 
the GMM context the MS has a PDP context activated. 

In lu mode only, integrity protected signalling (see subclause 4.1.1.1.1 of the present document and in general, see 
3GPP TS 33.102 [5a]) is mandatory. In lu mode only, all protocols shall use integrity protected signalling. Integrity 
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protection of all SM signalling messages is the responsibility of lower layers. It is the network which activates integrity 
protection. This is done using the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44. 118 [111]). 

For the session management protocol, the extended TI mechanism may be used (see 3GPP TS 24.007 [20]). 

6.1 .2 Session management states 

In this subclause, the SM states are described for one SM entity (see 3GPP TS 24.007 [20]). Each SM entity is 
associated with one PDP context or MBMS context. Subclause 6.1.2.1 describes the SM states in the MS and 
subclause 6.1.2.2 describes the SM states on the network side. 

6.1 .2.1 Session management states in the MS 

In this subclause, the possible states of an SM entity in the mobile station are described. As illustrated in figure 
6.1/3GPP TS 24.008 and 6.1a/3GPP TS 24.008 there are seven SM states in the MS. 

6.1.2.1.1 PDP-INACTIVE 

This state indicates that neither PDP context nor MBMS context exist. 

6.1.2.1.2 PDP-ACTIVE-PENDING 

This state exists when PDP context activation was requested by the MS. 

6.1.2.1.3 PDP-INACTIVE-PENDING 

This state exists when deactivation of the PDP contexts was requested by the MS. 

6.1.2.1.4 PDP-ACTIVE 

This state indicates that the PDP context is active. 

6.1.2.1.5 PDP-MODIFY_PENDING 

This state exists when modification of the PDP context was requested by the MS. 

6.1.2.1.6 MBMS-ACTIVE-PENDING 

This state exists when the MS has requested the network to activate an MBMS context. 

6.1.2.1.7 MBMS-ACTIVE 

This state indicates that the MBMS context is active. 
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DR (DEACTIV. PDF 
CONTX. REQ) 



DR: GMMSM-DATA-REQUEST (Message), i.e. message sent by an MS 

DI: GMMSM-DATA-INDICATION (Message), i.e. message received by an MS 



DR (MOD PDF CONTXT REJ) 



Figure 6.1/3GPP TS 24.008: Session management states for PDP context handling in the MS 

(overview) 

It shall be noted, that Figure 6.1/3GPP TS 24.008 applies to both the PDP context activation procedure and the 
secondary PDP context activation procedure, though the distinction in messages regarding the activation of PDP 
contexts is not shown here for simplicity. 
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DI (REQ. MBMS CONTX. ACTIV) •«■ 




DR (ACTIV. MBMS 
CONTX. REQ) 



DR (DEACTIV. PDF 
CONTX. ACC) 




DI (ACTIV. MBMS CONTX. REJ) 



DI (DEACTIV. PDF CONTX. REQ) 



DI (ACTIV. MBMS CONTX. ACC) 




DR: GMMSM-DATA-REQUEST (Mrasage), i.e. message sent by an MS 

DI: GMMSM-DATA-INDICATION (Mes.sage), i.e. message received by an MS 

Figure 6.1a/3GPP TS 24.008: Session management states for lUIBIUIS context hiandling in thie lUIS 

(overview) 

6.1 .2.2 Session management states on the network side 

In this subclause, the possible states of an SM entity on the network side are described. As illustrated in figures 
6.2/3GPP TS 24.008 and 6.2a/3GPP TS 24.008 there are eight SM states on the network side. 

6.1.2.2.1 PDP-INACTIVE 

This state indicates that the PDP context or MBMS context is not active. 

6.1.2.2.2 PDP-ACTIVE-PENDING 

This state exists when the PDP context activation was initiated by the network. 

6.1.2.2.3 PDP-INACTIVE-PENDING 

This state exists when deactivation of the PDP context was requested by the network. 

6.1.2.2.4 PDP-ACTIVE 

This state indicates that the PDP context is active. 

6.1.2.2.5 PDP-MODIFY-PENDING 

This state exists when modification of the PDP context was requested by the network. 
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6.1.2.2.6 MBMS-ACTIVE-PENDING 

This state exists when the network has initiated MBMS context activation. 

6.1.2.2.7 MBMS-INACTIVE-PENDING 

This state exists when the network has requested the MS to deactivate an MBMS context. 

6.1.2.2.8 MBMS-ACTIVE 

This state indicates that the MBMS context is active. 



(REQ PDF CONTX. ACTIV) 




DR: GMMSM-DATA-REQUEST (Message), i.e. message .sent by network 

DI: GMMSM-DATA-INDICATION (Message), i.e. message received by llie nelwoA 

Figure 6.2/3GPP TS 24.008: Session management states for PDP context handling on the network 

side (overview) 

It shall be noted, that figure 6.2/3GPP TS 24.008 applies to both the PDP context activation procedure and the 
secondary PDP context activation procedure, though the distinction in messages regarding the activation of PDP 
contexts is not shown here for simplicity. 
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DR: GMMSM-DATA-REQUEST (Message), i.e. message sent by network 

DI: GMMSM-DATA-INDICATION (Message), i.e. message received by the network 

Figure 6.2a/3GPP TS 24.008: Session management states for IVIBIUIS context handling on the network 

side (overview) 

6.1 .2A PDP address allocation 
6.1.2A.1 General 

PDP addresses are handled differently for PDN interworking of type PPP and IP (IPv4 or IPv6). 



6.1.2A.1.1 



Interworking with PDN based on IP 



During PDP context activation (see subclause 6.1.3.1), the MS can configure an IPv4 address, or obtain an IPv6 
interface identifier to be used during the lETF-based IP address allocation after PDP context establishment. 

The MS can obtain an IPv4 address or an IPv6 prefix via an lETF-based IP address allocation mechanism once the PDP 
context is established. 

The following lETF-based IP address/prefix allocation methods are specified for GPRS (the corresponding procedures 
are specified in 3GPP TS 29.061 [130]): 

a) /64 IPv6 default prefix allocation via IPv6 stateless address autoconfiguration. Optionally, allocation of 
additional IPv6 prefix(es) with length /64 or shorter via stateful DHCPv6 Prefix Delegation (see 
IETF RFC 3633 [139]); 

b) IPv4 address allocation and IPv4 parameter configuration via DHCPv4; 

Upon deactivation of a default PDP context, the MS shall locally release any IPv4 address or IPv6 prefix allocated to 
the MS for the corresponding PDN connection. 



6.1.2A.1.2 



Interworking with PDN based on PPP 



During PDP context activation no PDP address is configured. Instead, such information is negotiated and configured 
during the NCP phase of PPP. 
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6.1 .2A.2 IP address allocation via NAS signalling 

The MS shall set the PDP type in the PDP address IE in the ACTIVATE PDP CONTEXT REQUEST message when 
requesting establishment of a default PDP context; the detailed rules with regards to IP version for MS and network side 
are defined in subclause 6.1.3.1. 

If the MS wants to use DHCPv4 for IPv4 address assignment, it shall indicate that to the network within the Protocol 
Configuration Options IE in the ACTIVATE PDP CONTEXT REQUEST. 

If the MS requests allocation of an IPv6 address, the network constructs it of two parts: a /64 IPv6 prefix and an 
interface identifier of 64 bits length. The IPv6 prefix part is not used immediately by the MS; however, the network 
shall use the same IPv6 prefix in subsequent procedures for lETF-based IP address allocation. The interface identifier is 
only used for building a unique link-local IPv6 address. 

6.1 .3 Session Management procedures 
6.1 .3.1 PDP context activation 

The purpose of this procedure is to establish a PDP context between the MS and the network for a specific QoS on a 
specific NS API. The PDP context activation may be initiated by the MS or the initiation may be requested by the 
network. 

An MS attached for emergency bearer services shall only request a PDP context with request type set to "emergency". If 
there already is a PDN connection for emergency bearer services established, the MS shall not request an additional 
PDN connection for emergency bearer services. The MS shall not request emergency bearer services in A/Gb mode or 
in GERAN lu mode. 

Each PDP address may be described by one or more PDP contexts in the MS or the network. The PDP Context 
Activation procedure is used to activate the default PDP context for a given PDP address and APN, i.e. a PDN 
connection, whereas all additional contexts associated to the same PDP address and APN are activated with the 
secondary PDP context activation procedure. An MS supporting SI mode shall keep the default PDP context activated 
during the lifetime of the PDN connection. An MS not supporting S 1 mode should apply the same behaviour (see 
3GPP TS 23.060 [74]). When more than one PDP context is associated to a PDP address, there shall be a Traffic Flow 
Template (TFT), including one or more packet filters, for each or all but one context. The downlink and uplink packet 
filters are considered separately. If present, the TFT shall be sent transparently either from the MS via the SGSN to the 
GGSN to enable packet classification and policing for downlink data transfer in the GGSN or from the GGSN via the 
SGSN to the MS to be used in a network requested secondary PDP context activation procedure (see subclause 6.1.3.2) 
and enable packet classification and policing for uplink data transfer in the MS (see 3GPP TS 23.060 [74]). 

For the purpose of requesting IP address allocation the MS shall set the PDP type number in the Requested PDP address 
information element in the ACTIVATE PDP CONTEXT REQUEST message based on its IP stack configuration (e.g. 
the per APN settings specified in 3GPP TS 23.060 [74]) as follows: 

a) An MS, which is IPv6 and IPv4 capable, and 

has not been allocated an IP address for this APN, shall set the PDP type number to "IPv4v6 address"; 

has been allocated an IPv4 address for this APN and received the SM cause #52, "single address bearers only 
allowed", and is requesting an IPv6 address, shall set the PDP type number to "IPv6 address"; 

has been allocated an IPv6 address for this APN and received the SM cause #52, "single address bearers only 
allowed", and is requesting an IPv4 address, shall set the PDP type number to "IPv4 address". 

b) An MS, which is only IPv4 capable, shall set the PDP type number to "IPv4 address". 

c) An MS, which is only IPv6 capable, shall set the PDP type number to "IPv6 address". 

d) When the IP version capability of the MS is unknown in the MS (as in the case when the MT and TE are 
separated and the capability of the TE is not known in the MT), the MS shall set the PDP type number to 
"IPv4v6 address". 
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On receipt of the ACTIVATE PDP CONTEXT REQUEST message sent by the MS, the network when allocating an IP 
address shall take into account the PDP type number, the operator policies of the home and visited network, and the 
user's subscription data. 

If the MS requests PDP type IPv4v6, but the network configuration dictates the use of IPv4 addressing only or 
IPv6 addressing only for this APN, the network shall override the PDP type requested by the MS to a single 
address PDP type (IPv4 or IPv6). In the ACTIVATE PDP CONTEXT ACCEPT message sent to the MS, the 
network sets the PDP type number to either "IPv4 address" or "IPv6 address" and the SM cause to #50, "PDP 
type IPv4 only allowed", or #51, "PDP type IPv6 only allowed", respectively (see subclause 6.1.3.1.1). The MS 
shall not subsequently request another PDP context to get a PDP Type different from the one allowed by the 
network. 

If the MS requests PDP type IPv4v6, but the operator uses single addressing per PDP context due to 
interworking with nodes of earlier releases, the network shall override the PDP type requested by setting the 
PDP type in the ACTIVATE PDP CONTEXT ACCEPT message sent to the MS to a single address PDP type. In 
the ACTIVATE PDP CONTEXT ACCEPT message sent to the MS, the network sets the PDP type number to 
either "IPv4 address" or "IPv6 address" and the SM cause to #52, "single address bearers only allowed" (see 
subclause 6.1.3.1.1). The MS should subsequently request another PDP context for the other PDP type to the 
same APN with a single address PDP type (IPv4 or IPv6) other than the one already activated. 

NOTE 1 : If the MT and TE are separated, the MS might not be able to use SM cause #52 "single address bearers 
only allowed" as a trigger for activating a second single-IP-stack PDP context. 

The MS, in a pre release 8 network not supporting IPv4/v6, could encounter other network reactions: 

If the MS requests PDP type IPv4v6, and the PDP type is changed to PDP type IPv4 and no SM cause is 
included the MS should request another PDP context for PDP type IPv6 to the same APN. 

NOTE 2: Some networks can respond with ACTIVATE PDP CONTEXT REJECT with SM cause #28 "unknown 
PDP address or PDP type". In that instance, the MS can attempt to establish dual-stack connectivity by 
performing two PDP context activation request procedures to activate an IPv4 PDP context and an IPv6 
PDP context, both to the same APN. 

6.1 .3.1 .1 Successful PDP context activation initiated by the mobile station 

In order to request a PDP context activation, the MS sends an ACTIVATE PDP CONTEXT REQUEST message to the 
network, enters the state PDP-ACTIVE-PENDING and starts timer T3380. The message contains the selected NSAPI, 
PDP type number and requested QoS. The MS shall ensure that the selected NSAPI is not currently being used by 
another Session Management entity in the MS. The MS may indicate the support of Network Requested Bearer Control 
procedures in the protocol configuration options information element. The MS supporting S 1 mode shall include 
interactive or background traffic class in the QoS requested. The MS not supporting S 1 mode should include interactive 
or background traffic class in the QoS requested. If there is a subscribed QoS profile available for the MS, the network 
may ignore the requested QoS and apply the subscribed QoS profile (see 3GPP TS 23.060 [74]). 

The MS shall set the request type to "initial request" when the MS is establishing connectivity to an additional PDN for 
the first time, i.e. when it is an initial attach to that PDN. The MS shall set the request type to "handover" when the 
connectivity to a PDN is established upon handover from a non-3GPP access network and the MS was connected to that 
PDN before the handover to the 3GPP access network. If the MS is establishing connectivity for emergency bearer 
services it shall set the request type to "emergency" and not include an APN in the ACTIVATE PDP CONTEXT 
REQUEST message. 

Upon receipt of the ACTIVATE PDP CONTEXT REQUEST message with request type set to "emergency" the 
network shall use the APN or the GGSN/PDN GW configured for emergency bearer services. 

Upon receipt of an ACTIVATE PDP CONTEXT REQUEST message with a PDP type number "IPv4v6 address" in the 
Requested PDP address information element, the network shall on sending the ACTIVATE PDP CONTEXT ACCEPT 

message: 

include the SM cause information element with cause #50 ("PDP type IPv4 only allowed"), if the requested PDN 
connectivity is accepted with the restriction that only PDP type IPv4 is allowed; or 

include the SM cause information element with cause #51 ("PDP type IPv6 only allowed"), if the requested PDN 
connectivity is accepted with the restriction that only PDP type IPv6 is allowed; or 
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include the SM cause information element with cause #52 ("single address bearers only allowed"), if the 
requested PDN connectivity is accepted with the restriction that only single IP version bearers are allowed. 

Upon receipt of an ACTIVATE PDF CONTEXT REQUEST message, the network selects a radio priority level based 
on the QoS negotiated and may reply with an ACTIVATE PDF CONTEXT ACCEPT message. 

If the ACTIVATE PDP CONTEXT REQUEST message included an NAS signalling low priority indication set to "MS 
is configured for NAS signalling low priority", the network shall store the NAS signalling low priority indication within 
the default PDP context. 

Upon receipt of the message ACTIVATE PDP CONTEXT ACCEPT the MS shall stop timer T3380, shall enter the 
state PDP -ACTIVE. If the protocol configuration options information element is present, the network may indicate the 
Bearer Control Mode that shall be used. If the protocol configuration options information element is not present or the 
Selected Bearer Control Mode parameter is not present in the protocol configuration options information element, the 
MS shall apply Bearer Control Mode 'MS only' for all active PDP contexts sharing the same PDP Address and APN. If 
the offered QoS parameters received from the network differ from the QoS requested by the MS, the MS shall either 
accept the negotiated QoS or initiate the PDP context deactivation procedure. If the Request type information element is 
not present, the network shall assume that the request type is "initial request". 

NOTE 1 : If the MS requested a value for a QoS parameter that is not within the range specified by 

3GPP TS 23.107 [81], the network should negotiate the parameter to a value that lies within the specified 
range. 

If the lower layers provide a L-GW Transport Layer Address value together with the ACTIVATE PDP CONTEXT 
REQUEST message and a PDN connection is established as a LIPA PDN connection due to the ACTIVATE PDP 
CONTEXT REQUEST message, then the SGSN shall store the L-GW Transport Layer Address value as the GGSN 
address in the PDP context of the LIPA PDN connection. If connectivity with the requested APN is accepted and the 
network considers this PDN connection a LIPA PDN connection, then subject to operator policy the SGSN shall 
include in the ACTIVATE PDP CONTEXT ACCEPT message the Connectivity type IE indicating "the PDN 
connection is considered a LIPA PDN connection". 

In A/Gb mode, the MS shall initiate establishment of the logical link for the LLC S API indicated by the network with 
the offered QoS and selected radio priority level if no logical link has been already established for that S API. If the 
offered QoS parameters received from the network differ from the QoS requested by the MS, the MS shall either accept 
the negotiated QoS or initiate the PDP context deactivation procedure. If the LLC SAPI indicated by the network can 
not be supported by the MS, the MS shall initiate the PDP context deactivation procedure. 

In lu mode, both the network and the MS shall store the LLC SAPI and the radio priority in the PDP context. If a lu 
mode to A/Gb mode system change is performed, the new SGSN shall initiate establishment of the logical link using 
the negotiated QoS profile, the negotiated LLC SAPI, and selected radio priority level stored in the PDP context as in a 
A/Gb mode to A/Gb mode Routing Area Update. 

An MS, which is capable of operating in A/Gb mode, shall use a valid LLC SAPI, while an MS which is not capable of 
operating in A/Gb mode shall indicate the LLC SAPI value as "LLC SAPI not assigned" in order to avoid unnecessary 
value range checking and any other possible confusion in the network. When the MS uses a valid LLC SAPI, the 
network shall return a valid LLC SAPI. The network shall return the "LLC SAPI not assigned" value only when the MS 
uses the "LLC SAPI not assigned" value. 

NOTE 2: The radio priority level and the LLC SAPI parameters, though not used in lu mode, shall be included in 
the messages, in order to support handover between lu mode and A/Gb mode networks. 

Upon receipt of the ACTIVATE PDP CONTEXT ACCEPT message with the Connectivity type IE indicating "the PDN 
connection is considered a LIPA PDN connection", the MS provides an indication to the upper layers that the 
connectivity is provided by a LIPA PDN connection. 

6.1 .3.1 .2 Successful PDP context activation requested by the network 

In order to request a PDP context activation, the network sends a REQUEST PDP CONTEXT ACTIVATION message 
to the MS and starts timer T3385. The message contains an offered PDP address. If available, the APN shall be included 
in the REQUEST PDP CONTEXT ACTIVATION message. 

Upon receipt of a REQUEST PDP CONTEXT ACTIVATION message if an APN is indicated in the message and the 
timer T3396 is running for the APN, the MS shall stop the timer T3396, and then either initiate the PDP context 
activation procedure as described in the previous subclause or reject the activation request by sending a REQUEST PDP 
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CONTEXT ACTIVATION REJECT message as described in subclause 6.1.3.1.4. If the REQUEST PDF CONTEXT 
ACTIVATION message did not contain an APN, then the MS shall stop the timer T3396 associated with a message that 
was sent without an APN. The value of the reject cause IE of the REQUEST PDP CONTEXT ACTIVATION REJECT 
message shall indicate the reason for rejection, e.g. "insufficient resources to activate another context". 

The ACTIVATE PDP CONTEXT REQUEST message sent by the MS in order to initiate the PDP context activation 
procedure shall contain the PDP address, PDP Type and APN requested by the network in the REQUEST PDP 
CONTEXT ACTIVATION message. 

Upon receipt of the ACTIVATE PDP CONTEXT REQUEST message, the network shall stop timer T3385. 

The same procedures then apply as described for MS initiated PDP context activation. 

6.1 .3.1 .3 Unsuccessful PDP context activation initiated by the MS 

Upon receipt of an ACTIVATE PDP CONTEXT REQUEST message the network may reject the MS initiated PDP 
context activation by sending an ACTIVATE PDP CONTEXT REJECT message to the MS. The message shall contain 
a cause code that typically indicates one of the following causes: 

# 8: Operator Determined Barring; 

# 26: insufficient resources; 

# 27: missing or unknown APN; 

#28: unknown PDP address or PDP type; 

# 29: user authentication failed; 

# 30: activation rejected by GGSN, Serving GW or PDN GW; 
#31: activation rejected, unspecified; 

# 32: service option not supported; 

# 33: requested service option not subscribed; 

# 34: service option temporarily out of order; 

# 35: NSAPI already used. The network shall not send this cause code (see note 1); 

# 50: PDP type IPv4 only allowed; 
#51: PDP type IPv6 only allowed; 

# 52: single address bearers only allowed; 

# 95 - 111 : protocol errors; or 

#1 12: APN restriction value incompatible with active PDP context. 

NOTE 1: Pre-R99 network may send this cause code. 

If the SM cause value is #26 "insufficient resources" or #27 "missing or unknown APN", the network may include a 
value for timer T3396 in the ACTIVATE PDP CONTEXT REJECT message. If the SM cause value is #26 "insufficient 
resources" and if the request type in the ACTIVATE PDP CONTEXT REQUEST was set to "emergency", the network 
shall not include a value for timer T3396. 

Upon receipt of an ACTIVATE PDP CONTEXT REJECT message, the MS shall stop timer T3380 and enter/remain in 
state PDP-INACTIVE. 

If the SM cause value is #26 "insufficient resources" and T3396 value IE is included: 

the MS shall take different actions depending on the timer value received for timer T3396: 

i) if the timer value of the timer T3396 indicates neither zero nor deactivated, the MS shall start timer T3396 
and: 
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- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent 
by the MS, until timer T3396 expires, the timer T3396 is stopped, the MS is switched off or the 
SIM/USIM is removed; and 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN 
was not included in the ACTIVATE PDP CONTEXT REQUEST message, until timer T3396 expires, the 
MS is switched off or the SIM/USIM is removed; 

ii) if the timer value indicates that this timer is deactivated, the MS: 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent 
by the MS, until the MS is switched off or the SIM/USIM is removed or the MS receives a REQUEST 
PDP CONTEXT ACTIVATION or REQUEST SECONDARY PDP CONTEXT ACTIVATION or 
MODIFY PDP CONTEXT REQUEST message with the same APN from the network; and 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN 
was not included in the ACTIVATE PDP CONTEXT REQUEST message, until the MS is switched off 
or the SIM/USIM is removed; and 

iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT 
REQUEST message for the same APN; 

if the MS is switched off when the timer T3396 is running, the MS shall behave as follows when the MS is 
switched on: 

let tl be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off 
and switch on. If tl is greater than t, then the timer shall be restarted with the value tl - t. If tl is equal to or 
less than t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall 
restart the timer with the value tl. 

If the SM cause value is #27 "missing or unknown APN" and T3396 value IE is included: 

the MS shall take different actions depending on the timer value received for timer T3396: 

i) if the timer value of the timer T3396 indicates neither zero nor deactivated, the MS shall start timer T3396 
and: 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent 
by the MS, until timer T3396 expires, the MS is switched off or the SIM/USIM is removed; and 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN 
was not included in the ACTIVATE PDP CONTEXT REQUEST message, until timer T3396 expires, the 
MS is switched off or the SIM/USIM is removed; 

ii) if the timer value indicates that this timer is deactivated, the MS: 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent 
by the MS, until the MS is switched off or the SIM/USIM is removed; and 

- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN 
was not included in the ACTIVATE PDP CONTEXT REQUEST message, until the MS is switched off 
or the SIM/USIM is removed; and 

iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT 
REQUEST message for the same APN; 

If the T3396 value IE is not included, the MS may send an ACTIVATE PDP CONTEXT REQUEST message for the 
same APN. If the APN was not included in the previous ACTIVATE PDP CONTEXT REQUEST message, the MS 
may send an ACTIVATE PDP CONTEXT REQUEST message without an APN. 

The MS may initiate a PDP context activation procedure for emergency bearer services even if the timer T3396 is 
running. 
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6.1 .3.1 .4 Unsuccessful PDP context activation requested by the network 

Upon receipt of the REQUEST PDP CONTEXT ACTIVATION message, the MS may reject the network requested 
PDP context activation by sending the REQUEST PDP CONTEXT ACTIVATION REJECT message to the network. 
The message contains the same TI as included in the REQUEST PDP CONTEXT ACTIVATION and an additional 
cause code that typically indicates one of the following causes: 

# 26: insufficient resources; 

#31: activation rejected, unspecified; 

# 40: feature not supported; or 
#95 - 111: protocol errors. 

The network shall stop timer T3385 and enter state PDP-INACTIVE. 

6.1.3.1.5 Abnormal cases 

The following abnormal cases can be identified: 

a) Expiry of timers 

In the mobile station: 

On the first expiry of the timer T3380, the MS shall resend the ACTIVATE PDP CONTEXT REQUEST and 
shall reset and restart timer T3380. This retransmission is repeated four times, i.e. on the fifth expiry of timer 
T3380, the MS shall release all resources possibly allocated for this invocation and shall abort the procedure; 
no automatic PDP context activation re-attempt shall be performed. 

On the network side: 

On the first expiry of the timer T3385, the network shall resend the message REQUEST PDP CONTEXT 
ACTIVATION and shall reset and restart timer T3385. This retransmission is repeated four times, i.e. on the 
fifth expiry of timer T3385, the network shall release possibly allocated resources for this activation and shall 
abort the procedure. 

b) Collision of MS initiated and network requested PDP context activation 

Dynamic PDP address collision case: 

If the MS uses dynamic PDP addressing that turns out to collide with the network requested PDP address, then 
there is no detection of collision specified but left for network implementation. 

Static PDP address collision detected within the mobile station: 

A collision of an MS initiated and a network requested PDP context activation procedure is identified by the 
MS when a REQUEST PDP CONTEXT ACTIVATION message is received from the network after the MS 
has sent an ACTIVATE PDP CONTEXT REQUEST message, the MS has not yet received an ACTIVATE 
PDP CONTEXT ACCEPT or ACTIVATE PDP CONTEXT REJECT message, and 

i) the MS is able to compare the PDP type, PDP address and APN requested in the ACTIVATE PDP 

CONTEXT REQUEST message with those requested in the REQUEST PDP CONTEXT ACTIVATION 
message and these parameters are equal; or 

ii) the MS is unable to compare these parameters in the two messages. 

NOTE: In general, the MS is unable to test if the PDP type, PDP address and APN in the REQUEST PDP 
CONTEXT ACTIVATION message are the same as those for the PDN to which it is attempting to 
activate a context. This is because the MS may have omitted one or more of the parameters in the 
ACTIVATE PDP CONTEXT REQUEST message, since it is relying on default values to be provided by 
the network. 

In the case of such a collision, the MS initiated PDP context activation shall take precedence over the 
network requested PDP context activation. In case (i), the MS shall discard the REQUEST PDP CONTEXT 
ACTIVATION message and shall wait for the network response to its ACTIVATE PDP CONTEXT 
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REQUEST message. In case (ii), the MS shall send a REQUEST PDF CONTEXT ACTIVATION REJECT 
message with the cause 'insufficient resources' to the network, and wait for the network response to its 
ACTIVATE PDF CONTEXT REQUEST message. 

Static PDF address collision detected on the network side: 

A collision is detected by the network in the case where the PDF address, PDF type and APN derived 
(according to 3GPP TS 23.060 [74] annex A) from the ACTIVATE PDF CONTEXT REQUEST message 
received from the MS match those in the REQUEST PDF CONTEXT ACTIVATION message sent to the 
MS. 

In the case of such a collision, the MS initiated PDF context activation shall take precedence over the 
network requested PDF context activation. The network shall terminate the network requested PDF context 
activation procedure, and proceed with the MS initiated PDF context activation procedure. 

c) MS initiated PDF context activation request for an already activated PDF context (on the network side) 

i) If the network receives a ACTIVATE PDF CONTEXT REQUEST message with the same combination 
of APN, PDP type and PDP address as an already activated PDP context, the network shall deactivate the 
existing PDP context and, if any, all the linked PDP contexts (matching the combination of APN, PDP 
type and PDP address), locally without notification to the MS and proceed with the requested PDP 
context activation. 

ii) Alternatively (different combination of APN, PDP type and PDP address), if the NS API matches that of 
an already activated PDP context, then the network shall deactivate only the existing PDP context locally 
without notification to the MS and proceed with the requested PDP context activation. 

It is an implementation option if the parameters used for comparison described in clause i) and ii) are the 
parameters provided in the (current and previous) ACTIVATE PDP CONTEXT REQUESTS or the parameters 
which are the result of the application of the selection rules defined in 3GPP TS 23.060 [74] Annex A. 2. 

The parameter provided in the current ACTIVATE PDP CONTEXT REQUEST can not be compared to the 
actually used parameters (result of application of selection rules defined in 3GPP TS 23.060 [74] Annex A.2) of 
the previously activated PDP contexts. 

If the network receives an ACTIVATE PDP CONTEXT REQUEST message with request type "emergency" and 
there already is a PDN connection for emergency bearer services existing, the network shall reject the request 
with cause code #31 "activation rejected, unspecified". 

d) Network initiated PDP context activation request for an already activated PDP context (on the mobile station 

side) 

If the MS receives a REQUEST PDP CONTEXT ACTIVATION message with the same combination of 
APN, PDP type and PDP address as an already activated PDP context, the MS shall deactivate the existing 
PDP context and, if any, all the linked PDP contexts (matching the combination of APN, PDP type and PDP 
address) locally without notification to the network and proceed with the requested PDP context activation. 

e) Additional MS initiated PDP context activation request received from an MS that is attached for emergency 
bearer services: 

If the MS is attached for emergency bearer services the network shall only accept the PDP context activation 
request for emergency services. The network shall reject any other PDP context activation request with cause 
code #31 "activation rejected, unspecified". 

f) Reception of the ACTIVATE PDP CONTEXT ACCEPT message and Bearer Control Mode violation 

If the Selected Bearer Control Mode indicates other value than 'MS only' in the ACTIVATE PDP CONTEXT 
ACCEPT message although the protocol configuration options information element was not present or the MS 
Support of Network Requested Bearer Control indicator was not present in the protocol configuration options 
information element of the corresponding ACTIVATE PDP CONTEXT REQUEST message, the MS shall 
ignore the Selected Bearer Control Mode parameter received from the network and apply Bearer Control Mode 
'MS only' for all active PDP contexts sharing the same PDP Address and APN. 
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Figure 6.3/3GPP TS 24.008: MS initiated PDP context activation procedure 
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Figure 6.4/3GPP TS 24.008: Networit initiated PDP context activation procedure 



Secondary PDP Context Activation Procedure 



The purpose of this procedure is to establish an additional PDP context between the MS and the network for a specific 
Traffic Flow Template (TFT) and QoS profile on a specific NSAPI, when one or more PDP contexts has/have already 
been established for the particular PDP address and APN. The MS shall include a request for a TFT if a PDP context 
without a TFT is presently active for the particular PDP address, or the BCM is 'MS/NW. Depending on the selected 
Bearer Control Mode being 'MS only' or 'MS/NW, the secondary PDP context activation procedure may either be 
initiated by the MS or by either the MS or the network, respectively. If there is a PDN connection for emergency bearer 
services established, the MS shall not initiate a secondary PDP context activation procedure for this connection unless 
triggered by the network. 
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6.1 .3.2.1 Successful Secondary PDP Context Activation Procedure Initiated by the MS 

In order to request a PDP context activation with the same PDP address and APN as an already active PDP context, the 
MS shall send an ACTIVATE SECONDARY PDP CONTEXT REQUEST message to the network, enter the state 
PDP-ACTIVE-PENDING and start timer T3380. The message shall contain the selected NSAPI. The MS shall ensure 
that the selected NSAPI is not currently being used by another Session Management entity in the MS. The message 
shall also include a QoS profile, a requested LLC SAPI and the Linked TI. The QoS profile is the requested QoS. If 
present, the TFT shall be sent transparently through the SGSN to the GGSN to enable packet classification and policing 
for downlink data transfer. 

Upon receipt of an ACTIVATE SECONDARY PDP CONTEXT REQUEST, the network shall validate the message by 
verifying the TI given in the Linked TI IE to be any of the active PDP context(s). The same GGSN address shall be 
used by the SGSN as for the already established PDP context(s) for that PDP address. The network shall select a radio 
priority level based on the QoS negotiated and shall reply with an ACTIVATE SECONDARY PDP CONTEXT 
ACCEPT message, if the request can be accepted. 

NOTE 1: If the MS requested a value for a QoS parameter that is not within the range specified by 3GPP TS 23.107 
[81], the network should negotiate the parameter to a value that lies within the specified range. 

Upon receipt of the message ACTIVATE SECONDARY PDP CONTEXT ACCEPT, the MS shall stop timer T3380 
and enter the state PDP-ACTIVE. If the offered QoS parameters received from the network differ from the QoS 
requested by the MS, the MS shall either accept the negotiated QoS or initiate the PDP context deactivation procedure. 

In A/Gb mode the MS shall initiate establishment of the logical link for the LLC SAPI indicated by the network with 
the offered QoS and selected radio priority level if no logical link has been already established for that SAPI. If the LLC 
SAPI indicated by the network can not be supported by the MS, the MS shall initiate the PDP context deactivation 
procedure. 

In lu mode, both SGSN and MS shall store the LLC SAPI and the radio priority in the PDP context. If an lu mode to 
A/Gb mode Routing Area Update is performed, the new SGSN shall initiate establishment of the logical link using the 
negotiated LLC SAPI, the negotiated QoS profile and selected radio priority level stored in the PDP context as in an 
A/Gb mode to A/Gb mode Routing Area Update. 

An MS, which is capable of operating in A/Gb mode, shall use a valid LLC SAPI, while an MS which is not capable of 
operating in A/Gb mode shall indicate the LLC SAPI value as "LLC SAPI not assigned" in order to avoid unnecessary 
value range checking and any other possible confusion in the network. When the MS uses a valid LLC SAPI, the 
network shall return a valid LLC SAPI. The network shall return the "LLC SAPI not assigned" value only when the MS 
uses the "LLC SAPI not assigned" value. 

NOTE 2: The radio priority level and the LLC SAPI parameters, though not used in lu mode, shall be included in 
the messages, in order to support handover between lu mode and A/Gb mode networks. 

6.1 .3.2.1a Successful Secondary PDP Context Activation Procedure Requested by the 

network 

In order to request a PDP context activation with the same PDP address and APN as an already active PDP context, the 
network shall send a REQUEST SECONDARY PDP CONTEXT ACTIVATION message to the MS and start timer 
T3385. The message contains the required QoS, Linked TI, and optionally protocol configuration options and a TFT. If 
present, the TFT shall be sent transparently through the SGSN to the MS to enable packet classification and policing for 
uplink and downlink data transfer. 

Upon receipt of a REQUEST SECONDARY PDP CONTEXT ACTIVATION message, the MS shall stop the timer 
T3396 if it is running for the APN associated with the PDP context and then either initiate the secondary PDP context 
activation procedure as described in the subclause 6.1.3.2.1 or shall reject the activation request by sending a 
REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT message as described in subclause 6.1.3.2.2a. 
The value of the reject cause IE of the REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT message 
shall indicate the reason for rejection, e.g. "insufficient resources to activate another context". 

The ACTIVATE SECONDARY PDP CONTEXT REQUEST message sent by the MS in order to initiate the secondary 
PDP context activation procedure shall contain the QoS and Linked TI required in the REQUEST SECONDARY PDP 
CONTEXT ACTIVATION message. The MS shall also include a TFT with the downlink packet filters as specified in 
the REQUEST SECONDARY PDP CONTEXT ACTIVATION message. 
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Upon receipt of the ACTIVATE SECONDARY PDP CONTEXT REQUEST message, the network shall stop timer 
T3385. 

The same procedures then apply as described for MS initiated secondary PDP context activation. 

6.1 .3.2.2 Unsuccessful Secondary PDP Context Activation Procedure initiated by the MS 

Upon receipt of an ACTIVATE SECONDARY PDP CONTEXT REQUEST message, the network may reject the MS 
initiated PDP context activation by sending an ACTIVATE SECONDARY PDP CONTEXT REJECT message to the 
MS. The message shall contain a cause code that typically indicates one of the following: 

# 26: insufficient resources; 

# 30: activation rejected by GGSN, Serving GW or PDN GW; 
#31: activation rejected, unspecified; 

# 32: service option not supported; 

# 33: requested service option not subscribed; 

# 34: service option temporarily out of order; 

# 41 : semantic error in the TFT operation; 

# 42: syntactical error in the TFT operation; 
#43: unknown PDP context; 

# 44: semantic errors in packet filter(s); 

# 45: syntactical errors in packet filter(s); 

# 46: PDP context without TFT already activated; 

# 48: request rejected. Bearer Control Mode violation; 

# 56: collision with network initiated request; 
#60: bearer handling not supported; or 

# 95 - 111: protocol errors. 

If the SM cause value is #26 "insufficient resources", the network may include a value for timer T3396 value IE in the 
ACTIVATE SECONDARY PDP CONTEXT REJECT message. 

If the ACTIVATE SECONDARY PDP CONTEXT REQUEST message is related to an already active LIPA PDN 
connection, then the network shall reply with an ACTIVATE SECONDARY PDP CONTEXT REJECT message with 
cause code "bearer handling not supported". 

Upon receipt of an ACTIVATE SECONDARY PDP CONTEXT REJECT message, the MS shall stop timer T3380 and 
enter the state PDP-INACTIVE. 

If the SM cause value is #26 "insufficient resources" and T3396 value IE is included: 

the MS takes different actions depending on the timer value received for T3396 value IE: 

i) if the timer value of T3396 value IE indicates neither zero nor deactivated, the MS shall start timer T3396 
and not try to send another ACTIVATE PDP CONTEXT REQUEST, ACTIVATE SECONDARY PDP 
CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN until timer 
T3396 expires, the timer T3396 is stopped, the MS is switched off or the SIM/USIM is removed; 

ii) if the timer value indicates that this timer is deactivated, the MS shall not send another ACTIVATE PDP 
CONTEXT REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP 
CONTEXT REQUEST messages for the same APN until the MS is switched off or the SIM/USIM is 
removed or the MS receives a REQUEST PDP CONTEXT ACTIVATION or REQUEST SECONDARY 
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PDP CONTEXT ACTIVATION or MODIFY PDP CONTEXT REQUEST message for the same APN from 
the network; or 

iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT 
REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT 
REQUEST messages for the same APN. 

If the T3396 value IE is not included, the MS may send an ACTIVATE PDP CONTEXT REQUEST, ACTIVATE 
SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN. 

If the MS is switched off when the timer T3396 is running, the MS behaves as follows when the MS is switched on: 

let tl be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off and 
switch on. If tl is greater than t, then the timer shall be restarted with the value tl - t. If tl is equal to or less than 
t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall restart the 
timer with the value tl. 

6.1 .3.2.2a Unsuccessful secondary PDP context activation requested by the network 

Upon receipt of the REQUEST SECONDARY PDP CONTEXT ACTIVATION message, the MS may reject the 
network requested secondary PDP context activation by sending the REQUEST SECONDARY PDP CONTEXT 
ACTIVATION REJECT message to the network. The message contains the same Tl as included in the REQUEST 
SECONDARY PDP CONTEXT ACTIVATION and an additional cause code that typically indicates one of the 
following causes: 

# 26: insufficient resources; 

#31: activation rejected, unspecified; 

# 40: feature not supported; 

# 41 : semantic error in the TFT operation; 

# 42: syntactical error in the TFT operation; 

# 43: unknown PDP context; 

# 44: semantic errors in packet filter(s); 

# 45: syntactical errors in packet filter(s); 

# 46: PDP context without TFT already activated; 

# 48: request rejected. Bearer Control Mode violation; or 
#95 - 111: protocol errors. 

The network shall stop timer T3385 and enter state PDP-INACTIVE. 

6.1.3.2.3 Abnormal cases 

The following abnormal cases can be identified: 

a) Expiry of timers 

In the mobile station: 

On the first expiry of the timer T3380, the MS shall resend the ACTIVATE SECONDARY PDP 
CONTEXT REQUEST and shall reset and restart timer T3380. This retransmission is repeated four 
times, i.e. on the fifth expiry of timer T3380, the MS shall release all resources possibly allocated for this 
invocation and shall abort the procedure; no automatic PDP context activation re-attempt shall be 
performed. 

On the network side: 
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On the first expiry of the timer T3385, the network shall resend the message REQUEST SECONDARY 
PDP CONTEXT ACTIVATION and shall reset and restart timer T3385. This retransmission is repeated 
four times, i.e. on the fifth expiry of timer T3385, the network shall release possibly allocated resources 
for this activation and shall abort the procedure. 

b) MS initiated secondary PDP context activation procedure for an already activated PDP context (On the network 
side) 

If the NS API matches that of an already activated PDP context, the network shall deactivate the existing PDP 
context locally without notification to the MS and proceed with the requested PDP context activation. The case 
of a TI match is described in subclause 8.3.2. 

c) no PDP context with linked TI activated (on the network side) 

The network shall then check whether there is an activated PDP context for the TI given in the Linked TI IE 
in the ACTIVATE SECONDARY PDP CONTEXT REQUEST message. If there is no active PDP context 
for the specified TI, the network shall reply with an ACTIVATE SECONDARY PDP CONTEXT REJECT 
message, cause code indicating "unknown PDP context". 

d) no PDP context with Linked TI activated (on the mobile station side) 

The MS shall check whether there is an activated PDP context for the TI given in the Linked TI IE in the 
REQUEST SECONDARY PDP CONTEXT ACTIVATION message. If there is no active PDP context for 
the specified TI, the MS shall reply with a REQUEST SECONDARY PDP CONTEXT ACTIVATION 
REJECT message, cause code indicating "unknown PDP context". 

e) MS initiated secondary PDP context activation procedure for a PDN connection established for emergency 
bearer services (on the network side) 

If the MS initiated secondary PDP context activation procedure is for a PDN connection established for 
emergency bearer services the network shall reply with an ACTIVATE SECONDARY PDP CONTEXT 
REJECT message, cause code indicating "activation rejected, unspecified". 

If there exists a PDP context for the TI given in the Linked TI IE, then the TFT in the request message is checked for 
different types of TFT IE errors as follows: 

a) Semantic errors in TFT operations: 

1) When the TFT operation is an operation other than "Create a new TFT" or "No TFT operation". 
The network shall reject the activation request with cause "semantic error in the TFT operation". 
The MS shall reject the activation request with cause "semantic error in the TFT operation". 

b) Syntactical errors in TFT operations: 

1) When the TFT operation = "Create a new TFT" and the packet filter list in the TFT IE is empty. 

2) When the TFT operation = "No TFT operation" with a non-empty packet filter list in the TFT IE. 

3) When there are other types of syntactical errors in the coding of the TFT IE, such as a mismatch 
between the number of packet filters subfield, and the number of packet filters in the packet filter list. 

The network shall reject the activation request with cause "syntactical error in the TFT operation". 

The MS shall reject the activation request with cause "syntactical error in the TFT operation". 

c) Semantic errors in packet filters: 

1) When a packet filter consists of conflicting packet filter components which would render the packet 
filter ineffective, i.e. no IP packet will ever fit this packet filter. How the network determines a 
semantic error in a packet filter is outside the scope of the present document. 

The network shall reject the activation request with cause "semantic errors in packet filter(s)". 

The MS shall reject the activation request with cause "semantic errors in packet filter(s)". 
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d) Syntactical errors in packet filters: 

1) When the TFT operation = "Create a new TFT" and two or more packet filters in the resultant TFT 
would have identical packet filter identifiers. 

2) When the TFT operation = "Create a new TFT" and two or more packet filters in all TFTs associated 
with this PDP address and APN would have identical packet filter precedence values. 

3) When there are other types of syntactical errors in the coding of packet filters, such as the use of a 
reserved value for a packet filter component identifier. 

In case 2) the network shall not diagnose an error, further process the new activation request and, if it was 
processed successfully, delete the old packet filters which have identical filter precedence values. 
Furthermore, by means of explicit peer-to-peer signalling between the MS and the network, the network shall 
deactivate the PDP context(s) for which it has deleted the packet filters. 

In cases 1) and 3) the network shall reject the activation request with cause "syntactical errors in packet 
filter(s)". 

In case 2) the MS shall not diagnose an error, further process the new activation request and, if it was 
processed successfully, delete the old packet filters which have identical filter precedence values. 
Furthermore, by means of explicit peer-to-peer signalling between the network and the MS, the MS shall 
deactivate the PDP context(s) for which it has deleted the packet filters. 

In cases 1) and 3) the MS shall reject the activation request with cause "syntactical errors in packet filter(s)". 

Otherwise, the network shall accept the activation request by replying to the MS with an ACTIVATE SECONDARY 
PDP CONTEXT ACCEPT message. In case of network requested secondary PDP context activation procedure the MS 
shall accept the activation request by replying to the network with an ACTIVATE SECONDARY PDP CONTEXT 
REQUEST message. 
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Figure 6.5/3GPP TS 24.008: MS initiated secondary PDP context activation procedure 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



279 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



Stai1:T3380' 



Stop-T3J80' 



Stop-T33S0' 



MS" 



Network 



REQUEST- SECOND ARY-PDP- C ONTEXT- ACTIVATIONH 
•< StaitTJJS?' 



ACTIVATE- SECOND ARY-PDP- C ONTEXT- REQUESTIT 
► Stop-T33S? 



ACTIVATE- SECONDARY-PDP-C ONTEXT- ACCEPTIJ 



or 



ACTIVATE- SECONDARY-PDP-C ONTEXT- REJECTIJ 



I J 

or 

REQUEST- SECONDARY-PDP-C ONTEXT- ACTIVATION-REJECT^ 

► Stop-T3 J8?' 



Figure 6.5a/3GPP TS 24.008: Network requested secondary PDP context activation procedure 



6.1.3.3 



PDP context modification procedure 



The PDP context modification procedure is invoked by the network or by the MS, in order to change the QoS 
negotiated, the Radio priority level, or the TFT, negotiated during the PDP context activation procedure, the secondary 
PDP context activation procedure or at previously performed PDP context modification procedures. Depending on the 
selected Bearer Control Mode, the MS or the network may also create and delete a TFT in an active PDP context. The 
procedure can be initiated by the network or the MS at any time when a PDP context is active. Only the network may 
modify or delete a TFT packet filter that the network has created and conversely only the MS may modify or delete a 
TFT packet filter that the MS has created. The MS shall not modify the QoS of the first PDP context that was 
established within the PDN connection. The MS not supporting S 1 mode should not modify the QoS of the first PDP 
context that was established within the PDN connection (see 3GPP TS 23.060 [74]). 

The PDP context modification procedure may also be invoked by the MS, in order to upgrade the maximum bit rate and 
to trigger the re-establishment of the radio access bearer for an activated PDP context which is preserved in the MS with 
maximum bit rate values of Okbit/s for both uplink and downlink (see 3GPP TS 23.060 [74]). 

NOTE 1: As described in 3GPP TS 23.060 [74], the MS only preserves PDP contexts with a TFT including packet 
filter(s) set by the MS. 

If 

the PDP Context Modification request is accepted by the network but the radio access bearer is not established; 
or 

the PDP Context Modification request is rejected with cause "insufficient resources" (see subclause 6.1.3.3.3), 

then the MS is not required to start a new PDP Context Modification procedure or to start a Service Request procedure 
in order to trigger the re-establishment of the radio access bearer. 

If there is a PDN connection for emergency bearer services established, the MS shall not request a modification of 
bearer resources for this PDN connection. 
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The network requested PDP context modification procedure may also be used to update the PDP address when external 
PDP address allocation is performed, in which case the MS receives the PDP address in the MODIFY PDP CONTEXT 
REQUEST (Network to MS direction) message. 

NOTE 2: The procedure may be initiated by the network due to an inter-SGSN Routing Area Updating when a PDP 
context is active. 

6.1 .3.3.1 Network initiated PDP Context Modification 

In order to initiate the procedure, the network sends the MODIFY PDP CONTEXT REQUEST message to the MS and 
starts timer T3386. The message shall contain the new QoS and the radio priority level and LLC SAPI that shall be used 
by the MS in A/Gb mode at the lower layers for the transmission of data related to the PDP context. The MODIFY PDP 
CONTEXT REQUEST message may also contain modified packet filters in the TFT information element that shall be 
applied to that specific PDP context. 

The network informs the MS about the Bearer Control Mode to be applied for all active PDP contexts sharing the same 
PDP Address and APN by including the selected Bearer Control Mode parameter in the protocol configuration options 
information element. This information is either explicitly given in the MODIFY PDP CONTEXT REQUEST message 
or implicitly given by not being present. The MS shall act according to the presence of the protocol configuration 
options information element and the value of the selected Bearer Control Mode parameter in the MODIFY PDP 
CONTEXT REQUEST message: 

if the protocol configuration options information element is not present, the MS shall apply Bearer Control Mode 
'MS only' for all active PDP contexts sharing the same PDP Address and APN. 

if the selected Bearer Control Mode parameter is not present in the protocol configuration options information 
element, the MS shall apply Bearer Control Mode 'MS only' for all active PDP contexts sharing the same PDP 
Address and APN. 

if the selected Bearer Control Mode parameter is present in the protocol configuration options information 
element, the MS shall apply Bearer Control Mode according to the value of this parameter for all active PDP 
contexts sharing the same PDP Address and APN. 

Upon receipt of the MODIFY PDP CONTEXT REQUEST message the MS shall stop the timer T3396 if it is running 
for the APN associated with the PDP context and reply with the MODIFY PDP CONTEXT ACCEPT message, if the 
MS accepts the new QoS and the indicated LLC SAPI. 

The network shall upon receipt of the MODIFY PDP CONTEXT ACCEPT message stop timer T3386. 

In A/Gb mode, the network shall establish, reconfigure or continue using the logical link with the new QoS for the LLC 
SAPI indicated in the MODIFY PDP CONTEXT REQUEST message. 

In lu mode, if the Radio Access Bearer supporting the PDP context is active, then the network shall reconfigure and 
continue using the Radio Access Bearer with the new QoS indicated in the MODIFY PDP CONTEXT REQUEST 
message; if the PDP context is preserved, then the network may re-establish a Radio Access Bearer with the new QoS 
indicated in the MODIFY PDP CONTEXT REQUEST message. 

6.1 .3.3.2 MS initiated PDP Context Modification accepted by the network 

In order to initiate the procedure, the MS sends the MODIFY PDP CONTEXT REQUEST message to the network, 
enters the state PDP-MODIFY-PENDING and starts timer T338L The message may contain the requested new QoS 
and/or the TFT and the requested LLC SAPI (used in A/Gb mode). If the selected Bearer Control Mode is 'MS/NW and 
the MS wants to modify the QoS, it shall include a TFT with packet filter(s), or if no packet filters are proposed to be 
either added, replaced or deleted, it shall include packet filter identifier(s) to indicate which packet filter(s) in the TFT is 
associated with the QoS change. If a PDP context is associated with a TFT containing packet filters established by both 
the MS and the network, the only parameters in the QoS profile of that PDP context the MS is allowed to modify are the 
bitrate parameters. 

Upon receipt of the MODIFY PDP CONTEXT REQUEST message, the network may reply with the MODIFY PDP 
CONTEXT ACCEPT message in order to accept the context modification. The reply message may contain the 
negotiated QoS and the radio priority level based on the new QoS profile and the negotiated LLC SAPI that shall be 
used in A/Gb mode by the logical link. 
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Upon receipt of the MODIFY PDP CONTEXT ACCEPT message, the MS shall stop the timer T3381. If the offered 
QoS parameters received from the network differs from the QoS requested by the MS, the MS shall either accept the 
negotiated QoS or initiate the PDP context deactivation procedure. 

If a modification of QoS is requested by the MS, which the network can not accept, being unable to provide the 
requested QoS, it should maintain the QoS negotiated as previously negotiated or propose a new QoS. That means that 
the network should not reject the MS initiated PDP context modification request due to the unavailability of the QoS. If 
the MS requested a value for a QoS parameter that is not within the range specified by 3GPP TS 23.107[81], the 
network should negotiate the parameter to a value that lies within the specified range. 

6.1 .3.3.3 MS initiated PDP Context Modification not accepted by the network 

Upon receipt of a MODIFY PDP CONTEXT REQUEST message, the network may reject the MS initiated PDP 
context modification request by sending a MODIFY PDP CONTEXT REJECT message to the MS. The message shall 
contain a cause code that typically indicates one of the following: 

# 26: insufficient resources; 

# 30: activation rejected by GGSN, Serving GW or PDN GW; 

# 32: Service option not supported; 

# 37: QoS not accepted; 

# 41 : semantic error in the TFT operation; 

# 42: syntactical error in the TFT operation; 

# 44: semantic errors in packet filter(s); 

# 45: syntactical errors in packet filter(s); 

# 48: request rejected. Bearer Control Mode violation; 

# 60: bearer handling not supported; or 

# 95 - 1 1 1 : protocol errors. 

If upon the reception of a MODIFY PDP CONTEXT REQUEST message the network fails to re-establish the radio 
access bearer for a PDP context whose maximum bit rate in uplink and downlink is set to Okbit/s, the network shall 
reply with MODIFY PDP CONTEXT REJECT with cause "insufficient resources". 

If a TFT modification was requested and the requested new TFT is not available, then MODIFY PDP CONTEXT 
REJECT shall be sent. 

The network shall reply with MODIFY PDP CONTEXT REJECT with cause "request rejected. Bearer Control Mode 
violation", if 

- the selected Bearer Control Mode is 'MS/NW and the MS requests to create a TFT for a PDP context that was 
established without TFT; 

the selected Bearer Control Mode is 'MS/NW and the MS requests to upgrade the QoS of a PDP context without 
downlink packet filters, unless uplink packet filters already exist for the PDP context and the MS requests with 
the same MODIFY PDP CONTEXT REQUEST message to create downlink packet filters ; 

the selected Bearer Control Mode is 'MS/NW and the MS requests to modify the QoS, but does not include a 
TFT with at least apacket filter identifiers to indicate which packet filters in the TFT that is associated with the 
QoS change; or 

the selected Bearer Control Mode is 'MS/NW and the MS requests to modify the QoS for a PDP context 
associated with a TFT containing packet filters established by both the MS and the network and the MS tries to 
modify other parameters than the bitrate parameters in the QoS profile of that PDP context. 

If the MS has requested to modify the QoS of a default PDP context, the network shall reply with MODIFY PDP 
CONTEXT REJECT with cause code "QoS not accepted". 
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If the MS has requested to modify the PDP context of a LIPA PDN connection, then the network shall reply with a 
MODIFY PDP CONTEXT REJECT message with cause code "bearer handling not supported". 

The TFT in the request message is checked by the receiver for different types of TFT IE errors as follows: 

a) Semantic errors in TFT operations: 

1) TFT operation = "Create a new TFT" when there is already an existing TFT for the PDP context. 

2) When the TFT operation is an operation other than "Create a new TFT" and there is no TFT for the PDP 
context. 

3) TFT operation = "Delete existing TFT" when there is already another PDP context with the same PDP 
address and APN without a TFT. 

4) TFT operation = "Delete packet filters from existing TFT" when it would render the TFT empty. 

In these cases the receiver shall not diagnose an error and perform the following actions to resolve the 
inconsistency: 

In case 1) the receiver shall further process the new activation request and, if it was processed successfully, 
delete the old TFT. 

In case 2) the receiver shall: 

further process the new request and, if no error according to list items b), c), and d) was detected, consider 
the TFT as successfully deleted, if the TFT operation is "Delete existing TFT" or "Delete packet filters from 
existing TFT"; 

process the new request as an activation request, if the TFT operation is "Add packet filters in existing TFT" 
or "Replace packet filters in existing TFT". 

In case 3) the receiver shall process the new deletion request and, after successful deletion of the TFT, deactivate 
the old PDP context with the same PDP address and APN without a TFT by explicit peer-to-peer signalling 
between the MS and the network. 

In case 4) the receiver shall further process the new request and, if no error according to list items b), c), and d) 
was detected, delete the existing TFT. After successful deletion of the TFT, if there was already another PDP 
context with the same PDP address and APN without a TFT, the receiver shall deactivate this old PDP context 
without a TFT by explicit peer-to-peer signalling between the MS and the network. 

b) Syntactical errors in TFT operations: 

1) When the TFT operation is an operation other than "Delete existing TFT" or "No TFT operation" and the 
packet filter list in the TFT IE is empty. 

2) TFT operation = "Delete existing TFT" or "No TFT operation" with a non-empty packet filter list in the TFT 
IE. 

3) TFT operation = "Replace packet filters in existing TFT" when a to be replaced packet filter does not exist in 
the original TFT. 

4) TFT operation = "Delete packet filters from existing TFT" when a to be deleted packet filter does not exist in 
the original TFT. 

5) TFT operation = "Delete packet filters from existing TFT" with a packet filter list also including packet 
filters in addition to the packet filter identifiers. 

6) When there are other types of syntactical errors in the coding of the TFT IE, such as a mismatch between the 
number of packet filters subfield, and the number of packet filters in the packet filter list. 

In case 3) the receiver shall not diagnose an error, further process the replace request and, if no error according 
to list items c) and d) was detected, include the packet filters received to the existing TFT. 

In case 4) the receiver shall not diagnose an error, further process the deletion request and, if no error according 
to list items c) and d) was detected, consider the respective packet filter as successfully deleted. 
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Otherwise the receiver shall reject the modification request with cause "syntactical error in the TFT operation". 

c) Semantic errors in packet filters: 

When a packet filter consists of conflicting packet filter components which would render the packet filter 
ineffective, i.e. no IP packet will ever fit this packet filter. How the receiver determines a semantic error in a 
packet filter is outside the scope of the present document. 

The receiver shall reject the modification request with cause "semantic errors in packet filter(s)". 

d) Syntactical errors in packet filters: 

1) When the TFT operation = "Create a new TFT" or "Add packet filters to existing TFT" and two or more 
packet filters in the resultant TFT would have identical packet filter identifiers. 

2) When the TFT operation = "Create a new TFT" or "Add packet filters to existing TFT" or "Replace packet 
filters in existing TFT" and two or more packet filters in all TFTs associated with this PDP address and APN 
would have identical packet filter precedence values. 

3) When there are other types of syntactical errors in the coding of packet filters, such as the use of a reserved 
value for a packet filter component identifier. 

In case 1), if two or more packet filters with identical packet filter identifiers are contained in the new request, 
the receiver shall reject the modification request with cause "syntactical errors in packet filter(s)". Otherwise, the 
receiver shall not diagnose an error, further process the new request and, if it was processed successfully, delete 
the old packet filters which have the identical packet filter identifiers. 

In case 2) the receiver shall not diagnose an error, further process the new request and, if it was processed 
successfully, delete the old packet filters which have identical filter precedence values. Furthermore, by means 
of explicit peer-to-peer signalling between the MS and the network, the receiver shall deactivate the PDP 
context(s) for which it has deleted the packet filters. 

Otherwise the receiver shall reject the modification request with cause "syntactical errors in packet filter(s)". 

If the SM cause value is #26 "insufficient resources", the network may include a value for timer T3396 value IE in the 
MODIFY PDP CONTEXT REJECT message. 

Upon receipt of a MODIFY PDP CONTEXT REJECT message, the MS shall stop timer T3381 and enter the state 
PDP-ACTIVE. 

If the SM cause value is #26 and T3396 value IE is included: 

the MS takes different actions depending on the timer value received for T3396 value IE: 

i) if the timer value of T3396 value IE indicates neither zero nor deactivated, the MS shall start timer T3396 
and not try to send another ACTIVATE PDP CONTEXT REQUEST, ACTIVATE SECONDARY PDP 
CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN until timer 
T3396 expires, the timer T3396 is stopped, the MS is switched off or the SIM/USIM is removed; 

ii) if the timer value indicates that this timer is deactivated, the MS shall not try to send another ACTIVATE 
PDP CONTEXT REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP 
CONTEXT REQUEST messages for the same APN until the MS is switched off or the SIM/USIM is 
removed or the MS receives REQUEST PDP CONTEXT ACTIVATION or REQUEST SECONDARY PDP 
CONTEXT ACTIVATION or MODIFY PDP CONTEXT REQUEST message for the same APN from the 
network; or 

iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT 
REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT 
REQUEST messages for the same APN. 

If the T3396 value IE is not included, the MS may send an ACTIVATE PDP CONTEXT REQUEST, ACTIVATE 
SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN. 

If the MS is switched off when the timer T3396 is running, the MS behaves as follows when the MS is switched on: 
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let tl be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off and 
switch on. If tl is greater than t, then the timer shall be restarted with the value tl - t. If tl is equal to or less than 
t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall restart the 
timer with the value tl. 

6.1 .3.3.3a Network initiated PDP Context Modification not accepted by the MS 

Upon receipt of a MODIFY PDP CONTEXT REQUEST message, if the MS does not accept the new QoS due to 
resource reasons or the indicated LLC SAPI, the MS shall initiate the PDP context deactivation procedure for the PDP 
context - the reject cause IE value of the DEACTIVATE PDP CONTEXT REQUEST message shall indicate "QoS not 
accepted". 

The MS may reject the network initiated PDP context modification request by sending a MODIFY PDP CONTEXT 
REJECT message to the network. The message shall contain a cause code that typically indicates one of the following: 

# 41 : semantic error in the TFT operation; 

# 42: syntactical error in the TFT operation; 

# 44: semantic errors in packet filter(s); 

# 45: syntactical errors in packet filter(s); 

# 48: request rejected, Bearer Control Mode violation; or 

# 95 - 1 1 1 : protocol errors. 

The MS shall reply with MODIFY PDP CONTEXT REJECT with cause "request rejected. Bearer Control Mode 
violation", if the selected Bearer Control Mode is 'MS only' and the network requests to modify or delete a TFT 

The TFT in the request message is checked by the receiver for different types of TFT IE errors as specified in 
subclause 6.1.3.3.3. 

Upon receipt of a MODIFY PDP CONTEXT REJECT message, the network shall stop timer T3386 and enter the state 
PDP-ACTIVE. 

6.1.3.3.4 Abnormal cases 

a) Expiry of timers 

On the network side: 

On the first expiry of timer T3386, the network shall resend the MODIFY PDP CONTEXT REQUEST 
message reset and restart timer T3386. This retransmission is repeated four times, i.e. on the fifth expiry of 
timer T3386, the network may continue to use the previously negotiated QoS or it may initiate the PDP 
context deactivation procedure. 

In the MS: 

On the first expiry of timer T3381, the MS shall resend the MODIFY PDP CONTEXT REQUEST message 
reset and restart timer T3381. This retransmission is repeated four times, i.e. on the fifth expiry of timer 
T3381, the MS may continue to use the previously negotiated QoS or it may initiate the PDP context 
deactivation procedure. 

b) Collision of MS and Network initiated PDP Context Modification Procedures 

A collision of a MS and network initiated PDP context modification procedures is identified by the MS if a 
MODIFY PDP CONTEXT REQUEST message is received from the network after the MS has sent a MODIFY 
PDP CONTEXT REQUEST message itself, and both messages contain the same Tl and the MS has not yet 
received a MODIFY PDP CONTEXT ACCEPT message from the network. 

A collision is detected by the network in case a MODIFY PDP CONTEXT REQUEST message is received from 
the MS with the same Tl as the MODIFY PDP CONTEXT REQUEST message sent to the MS. 
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In the case of such a collision, the network initiated PDP context modification shall take precedence over the MS 
initiated PDP context modification. The MS shall terminate internally the MS initiated PDP context modification 
procedure, enter the state PDP- Active and proceed with the network initiated PDP context modification 
procedure by sending a MODIFY PDP CONTEXT ACCEPT message. The network shall ignore the MODIFY 
PDP CONTEXT REQUEST message received in the state PDP-MODIFY-PENDING. The network shall 
proceed with the network initiated PDP context modification procedure as if no MODIFY PDP CONTEXT 
REQUEST message was received from the MS. 

c) Collision of MS initiated PDP Context Modification Procedures and Network initiated Deactivate PDP Context 

Request Procedures 

A collision of a MS initiated PDP context modification procedures and a network initiated PDP context 
deactivation procedures is identified by the MS if a DEACTIVATE PDP CONTEXT REQUEST message is 
received from the network after the MS has sent a MODIFY PDP CONTEXT REQUEST message, and the MS 
has not yet received a MODIFY PDP CONTEXT ACCEPT message from the network. 

In the case of such a collision, the network initiated PDP context deactivation shall take precedence over the MS 
initiated PDP context modification. The MS shall terminate internally the MS initiated PDP context modification 
procedure, and proceed with the network initiated PDP context deactivation procedure by sending a 
DEACTIVATE PDP CONTEXT ACCEPT, enter the state PDP-INACTIVE. The network shall ignore the 
MODIFY PDP CONTEXT REQUEST message received in the state PDP-INACTIVE-PENDING. The network 
shall proceed with the network initiated PDP context deactivation procedure as if no MODIFY PDP CONTEXT 
REQUEST message was received from the MS. 

d) MS initiated PDP context modification procedure for a PDN connection established for emergency bearer 
services. 

The network shall reply with a MODIFY PDP CONTEXT REJECT message with a cause code indicating 
"activation rejected by GGSN, Serving GW or PDN GW". 
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Figure 6.6/3GPP TS 24.008: Network initiated PDP context modification procedure 
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Figure 6.7/3GPP TS 24.008: IVIS initiated PDP context modification procedure 



6.1.3.4 



PDP context deactivation procedure 



The purpose of this procedure is to deactivate an existing PDP context between the MS and the network. The PDP 
context deactivation may be initiated by the MS or by the network. The tear down indicator information element may 
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be included in the DEACTIVATE PDP CONTEXT REQUEST message in order to indicate whether only the PDP 
context associated with this specific TI or all active PDP contexts sharing the same PDP address and APN as the PDP 
context associated with this specific TI shall be deactivated. If the tear down is requested, all other active PDP contexts 
sharing the same PDP address and APN as the PDP context associated with this specific TI shall be deactivated locally 
without peer-to-peer signalling. If the tear down indicator information element is not included in the DEACTIVATE 
PDP CONTEXT REQUEST message, only the PDP context associated with this specific TI shall be deactivated. 

An MS supporting S 1 mode shall always include the tear down indicator when deactivating the default PDP context. An 
MS not supporting SI mode should apply the same behavior (see 3GPP TS 23.060 [74]). 

After successful PDP context deactivation, the associated NSAPI and TI values are released and can be reassigned to 
another PDP context. 

If one or more MBMS contexts are linked to a PDP context that has been deactivated, the MS shall deactivate all those 
MBMS contexts locally (without peer to peer signalling between the MS and the network). 

The MS is allowed to initiate the PDP context deactivation procedure even if the timer T3396 is running. 

6.1 .3.4.1 PDP context deactivation initiated by the MS 

In order to deactivate a PDP context, the MS sends a DEACTIVATE PDP CONTEXT REQUEST message to the 
network, enters the state PDP-INACTIVE-PENDING and starts timer T3390. The message contains the transaction 
identifier (TI) in use for the PDP context to be deactivated and a cause code that typically indicates one of the following 

causes: 

# 25: LLC or SNDCP failure (A/Gb mode only); 

# 26: insufficient resources; 

# 36: regular deactivation; or 

# 37: QoS not accepted. 

The network shall reply with the DEACTIVATE PDP CONTEXT ACCEPT message. Upon receipt of the 
DEACTIVATE PDP CONTEXT ACCEPT message, the MS shall stop timer T3390. 

In A/Gb mode, both the MS and the network shall initiate local release of the logical link if it is not used by another 
PDP context. 

In lu mode, the network shall initiate the release of Radio Access Bearer associated with this PDP context. 

If the selected Bearer Control Mode is 'MS/NW the MS should not deactivate a PDP context, if it is the only PDP 
context without TFT within a group of active PDP contexts sharing the same PDP address and APN. 

NOTE 1 : A configuration with more than one PDP context without TFT within a group of active PDP contexts 

sharing the same PDP address and APN can occur during a network initiated PDP context modification 
due to asynchronous TFT states in the MS and in the network (see e.g. subclause 6.1.3.3.3 bullet a.3). 

NOTE 2: If the MS deactivates the last PDP context without TFT within a group of active PDP contexts sharing the 
same PDP address and APN, the network will initiate the re-establishment of this PDP context using the 
network requested secondary PDP context activation procedure. 



6.1 .3.4.2 PDP context deactivation initiated by the networl< 

In order to deactivate a PDP context, the network sends a DEACTIVATE PDP CONTEXT REQUEST message to the 
MS and starts timer T3395. The message contains the transaction identifier in use for the PDP context to be deactivated 
and a cause code that typically indicates one of the following causes: 

# 8: Operator Determined Barring; 

# 25: LLC or SNDCP failure (A/Gb mode only); 

# 36: regular deactivation; 
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# 38: network failure; or 

# 39: reactivation requested. 

#1 12: APN restriction value incompatible with active PDP context. 

The MS shall, upon receipt of this message, reply with a DEACTIVATE PDP CONTEXT ACCEPT message. Upon 
receipt of the DEACTIVATE PDP CONTEXT ACCEPT message, the network shall stop the timer T3395. 

If the DEACTIVATE PDP CONTEXT REQUEST message includes the cause #39 "reactivation requested" and the 
PDP context was activated by the MS, the MS should stop timer T3396 if it is running for the APN associated with the 
PDP context, and re-activate the PDP context. Additionally, the MS should re-activate the PDP contexts that were 
originally activated by the MS and released by the network as a result of this PDP context deactivation procedure. 

NOTE: User interaction is necessary in some cases when the MS cannot re-activate the PDP context(s) 
automatically. 

If a detach is requested by the HLR for an MS that has PDP contexts for emergency services, the SGSN shall send a 
DEACTIVATE PDP CONTEXT REQUEST message to the MS for all the PDP contexts that are not PDP contexts for 
emergency services. 

If the network operates in network operation mode I, ISR is activated and the MS has indicated support of EMM 
combined procedures in MS network capability, when the SGSN receives the request from the Serving GW for 
deactivating the last PDP context, then the SGSN shall perform a detach procedure for non-GPRS services only as 
described in subclause 4.7.4.2. 

In A/Gb mode, both the MS and the network shall initiate local release of the logical link if it is not used by another 
PDP context. 

In lu mode, the network shall initiate the release of Radio Access Bearer associated with this PDP context. 

6.1.3.4.3 Abnormal cases 

The following abnormal cases can be identified: 

a) Expiry of timers 

In the mobile station: 

On the first expiry of timer T3390, the MS shall resent the message DEACTIVATE PDP CONTEXT 
REQUEST and shall reset and restart the timer T3390. This retransmission is repeated four times, i.e. on the 
fifth expiry of timer T3390, the MS shall release all resources allocated and shall erase the PDP context 
related data. 

On the network side: 

On the first expiry of timer T3395, the network shall resent the message DEACTIVATE PDP CONTEXT 
REQUEST and shall reset and restart timer T3395. This retransmission is repeated four times, i.e. on the fifth 
expiry of timer T3395, the network shall erase the PDP context related data for that MS. 

b) Collision of MS and network initiated PDP context deactivation requests 

If the MS and the network initiated PDP context deactivation requests collide, the MS and the network shall each 
reply with the messages DEACTIVATE PDP CONTEXT ACCEPT and shall stop timer T3390 and T3395, 
respectively. 
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Figure 6.8/3GPP TS 24.008: MS initiated PDP context deactivation procedure 
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Figure 6.9/3GPP TS 24.008: Networit initiated PDP context deactivation procedure 



6.1.3.4a 



Void 



6.1.3.5 



Void 



6.1.3.5a Notification procedure 



6.1.3.5a.1 



General 



The network can use the notification procedure to inform the MS about events which are relevant for the upper layer 
which is using a PDP context or has requested a session management procedure. 

If the MS has indicated that it supports the notification procedure, the network may initiate the procedure at any time 
while a PDP context is activated or another session management procedure is ongoing. 



6.1.3.5a.2 



Notification procedure initiation by the network 



The network initiates the notification procedure by sending a NOTIFICATION message to the MS (see example in 
figure 6.9a/3GPP TS 24.008). 
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6.1.3.5a.3 



Figure 6.9a/3GPP TS 24.008: Notification procedure 



Notification procedure in the MS 



When the MS receives a NOTIFICATION message, the SM protocol entity in the MS shall provide the notification 
indicator to the upper layer. 

The notification indicator can have the following value: 

#1: SRVCC handover cancelled, IMS session re-establishment required. 



6.1.3.6 



Receiving a SIVI STATUS message by a SIVI entity 



If the SM entity of the MS receives an SM STATUS message the MS shall take different actions depending on the 
received SM cause value: 

#8 1 Invalid transaction identifier value 

The MS shall abort any ongoing SM procedure related to the received transaction identifier value, stop any 
related timer, and deactivate the corresponding PDP or MBMS context locally (without peer to peer signalling 
between the MS and the network). 

If one or more MBMS contexts are linked to a PDP context that has been deactivated, the MS shall deactivate all 
those MBMS Contexts locally (without peer to peer signalling between the MS and the network). 

#97 Message type non-existent or not implemented 

The MS shall abort any ongoing SM procedure related to the received transaction identifier value and stop any 
related timer. 

If the SM entity of the MS receives a SM STATUS message with any other SM cause value no state transition and no 
specific action shall be taken as seen from the radio interface, i.e. local actions are possible. 

If the SM entity of the network receives an SM STATUS message the network shall take different actions depending on 
the received SM cause value: 

#8 1 Invalid transaction identifier value 

The network shall abort any ongoing SM procedure related to the received transaction identifier value, stop any 
related timer, and deactivate the corresponding PDP or MBMS context locally (without peer to peer signalling 
between the MS and the network). 
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If one or more MBMS contexts are linked to a PDP context that has been deactivated, the MS shall deactivate all 
those MBMS Contexts locally (without peer to peer signalling between the MS and the network). 

#97 Message type non-existent or not implemented 

The network shall abort any ongoing SM procedure related to the received transaction identifier value and stop 
any related timer. 

The actions to be taken in the network on receiving a SM STATUS message with any other SM cause value are an 
implementation dependent option. 

6.1 .3.7 Protocol configuration options 

The MS and the GGSN may communicate parameters by means of the protocol configuration options information 
element when activating, modifying or deactivating a PDP context. Such parameters can e.g. be used to convey 
information from external protocols between the MS and the GGSN. An overview of how the protocol configuration 
options information element is used is specified in 3GPP TS 27.060 [36a]. 

The protocol configuration options information element is transparent to the SGSN. 

6.1 .3.8 MBMS context activation 

The purpose of this procedure is to establish an MBMS context in the MS and in the network for a specific IP Multicast 
Address using a specific NSAPI for MBMS user plane transmission. The MS shall only initiate the MBMS context 
activation when requested by the network. However, the trigger for the activation request by the network is initiated by 
the MS at the appHcation layer (see 3GPP TS 23.246 [106]). 

6.1 .3.8.1 Successful MBMS context activation 

In order to request an MBMS context activation, the network sends a REQUEST MBMS CONTEXT ACTIVATION 
message to the MS, enters the state MBMS-ACTIVE-PENDING and starts timer T3385. The message shall contain the 
IP multicast address, the APN and the Linked NSAPI. 

Upon receipt of a REQUEST MBMS CONTEXT ACTIVATION message, the MS shall validate the message by 
verifying the NSAPI given in the Linked NSAPI IE to be one of the active PDP context(s), stop the timer T3396 if it is 
running for the APN indicated in the message and send an ACTIVATE MBMS CONTEXT REQUEST, enter state 
MBMS-ACTIVE-PENDING and start timer T3380. The message shall contain an IP multicast address and an APN, 
which shall be the same as the IP multicast address and the APN requested by the network in the REQUEST MBMS 
CONTEXT ACTIVATION message. Furthermore, the MS shall include the Supported MBMS bearer capabilities, i.e. 
the maximum downlink bit rate the MS can handle. 

Upon receipt of the ACTIVATE MBMS CONTEXT REQUEST message, the network shall stop timer T3385. If the 
network accepts the request, it shall reply with an ACTIVATE MBMS CONTEXT ACCEPT message. 

Upon receipt of the message ACTIVATE MBMS CONTEXT ACCEPT the MS shall stop timer T3380 and shall enter 
the state MBMS -ACTIVE. 
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6.1 .3.8.2 Unsuccessful MBMS context activation requested by the MS 

Upon receipt of an ACTIVATE MBMS CONTEXT REQUEST message the network may reject the MS initiated 
MBMS context activation by sending an ACTIVATE MBMS CONTEXT REJECT message to the MS. The sender of 
the message shall include the same TI as included in the ACTIVATE MBMS CONTEX REQUEST and an additional 
cause code that typically indicates one of the following causes: 

#8: Operator Determined Barring; 

# 24: MBMS bearer capabilities insufficient for the service; 

# 26: insufficient resources; 

# 27: missing or unknown APN; 

# 29: user authentication failed; 

# 30: activation rejected by GGSN, Serving GW or PDN GW; 
#31: activation rejected, unspecified; 

# 32: service option not supported; 

# 33: requested service option not subscribed; 

# 34: service option temporarily out of order; or 

# 95 - # 111 : protocol errors. 

If the SM cause value is #26 "insufficient resources" or #27 "missing or unknown APN", the network may include a 
value for timer T3396 in the ACTIVATE MBMS CONTEXT REJECT message. 

Upon receipt of an ACTIVATE MBMS CONTEXT REJECT message, the MS shall stop timer T3380 and enter/remain 
in state PDP-INACTIVE. 

If the SM cause value is #26 "insufficient resources" and T3396 value IE is included: 

the MS shall take different actions depending on the timer value received for timer T3396: 

i) if the timer value indicates neither zero nor deactivated, the MS shall start timer T3396 and not send another 
ACTIVATE MBMS CONTEXT REQUEST message for the same APN until timer T3396 expires, the timer 
T3396 is stopped, the MS is switched off or the SIM/USIM is removed or the MS receives REQUEST 
MBMS CONTEXT ACTIVATION message for the same APN from the network; 

ii) if the timer value indicates that this timer is deactivated, the MS shall not send another ACTIVATE MBMS 
CONTEXT REQUEST message for the same APN until the MS is switched off or the SIM/USIM is removed 
or the MS receives REQUEST MBMS CONTEXT ACTIVATION message for the same APN from the 
network; 

iii) if the timer value indicates that this timer is zero, the MS may send another ACTIVATE MBMS CONTEXT 
REQUEST message for the same APN; and 

if the MS is switched off when the timer T3396 is running, the MS shall behave as follows when the MS is 
switched on: 

let tl be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off 
and switch on. If tl is greater than t, then the timer shall be restarted with the value tl - t. If tl is equal to or 
less than t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall 
restart the timer with the value tl. 

If the SM cause value is #27 "missing or unknown APN" and T3396 value IE is included: 

the MS shall take different actions depending on the timer value received for timer T3396: 

i) if the timer value of the timer T3396 indicates neither zero nor deactivated, the MS shall start timer T3396 
and not send an ACTIVATE MBMS CONTEXT REQUEST message for the same APN until timer T3396 
expires, the MS is switched off or the SIM/USIM is removed; 
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ii) if the timer value indicates that this timer is deactivated, the MS shall not send another ACTIVATE MBMS 
CONTEXT REQUEST message for the same APN until the MS is switched off or the SIM/USIM is 
removed; and 

iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE MBMS CONTEXT 
REQUEST message for the same APN. 

If the T3396 value IE is not included, the MS may send an ACTIVATE MBMS CONTEXT REQUEST message for the 
same APN. 

6.1 .3.8.3 Unsuccessful MBMS context activation requested by the networl< 

Upon receipt of the REQUEST MBMS CONTEXT ACTIVATION message, the MS may reject the network requested 
MBMS context activation by sending the REQUEST MBMS CONTEXT ACTIVATION REJECT message to the 
network. The sender of the message shall include the same TI as included in the REQUEST MBMS CONTEXT 
ACTIVATION and an additional cause code that typically indicates one of the following causes; 

# 26: insufficient resources; 

#31: activation rejected, unspecified; 

# 40: feature not supported; or 

# 95 - # 11 1 : protocol errors. 

The network shall stop timer T3385 and enter in state PDP-INACTIVE. 

6.1.3.8.4 Abnormal cases 

The following abnormal cases can be identified: 

a) Expiry of timers in the mobile station: On the first expiry of the timer T3380, the MS shall resend the 
ACTIVATE MBMS CONTEXT REQUEST and shall reset and restart timer T3380. This retransmission is 
repeated four times, i.e. on the fifth expiry of timer T3380, the MS shall release all resources possibly allocated 
for this invocation and shall abort the procedure; no automatic MBMS context activation re-attempt shall be 
performed. 

b) Expiry of timers on the network side: On the first expiry of the timer T3385, the network shall resend the 
message REQUEST MBMS CONTEXT ACTIVATION and shall reset and restart timer T3385. This 
retransmission is repeated four times, i.e. on the fifth expiry of timer T3385, the network shall release possibly 
allocated resources for this activation and shall abort the procedure. 

c) MBMS context activation request for an already activated MBMS context (on the mobile station side): If the 
MS receives a REQUEST MBMS CONTEXT ACTIVATION message with the same combination of APN and 
IP multicast address (i.e. PDP type and PDP address) as an already activated MBMS context, the MS shall 
deactivate the existing MBMS context locally without notification to the network and proceed with the requested 
MBMS context activation. 

d) MBMS context activation request for an already activated MBMS context (on the network side): If the network 
receives an ACTIVATE MBMS CONTEXT REQUEST message with the same combination of APN and IP 
multicast address (i.e. PDP type and PDP address) as an already activated MBMS context, the network shall 
deactivate the existing MBMS context locally without notification to the MS and proceed with the requested 
MBMS context activation. 
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Figure 6.10/3GPP TS 24.008: MBMS context activation procedure 



6.1.3.9 



MBMS context deactivation 



The purpose of this procedure is to deactivate an existing MBMS context in the MS and the network. The MS shall only 
initiate the MBMS context deactivation when requested by the network, however the trigger for the deactivation request 
by the network may be initiated by the MS at application layer or by the network, see 3GPP TS 23.246 [106]. 

After a successful MBMS context deactivation, the associated MBMS NSAPl and TI values shall be released in both 
the MS and the network and can be reassigned to another MBMS context. 

The MBMS context deactivation procedure makes use of the messaging and signalling of the PDF context deactivation 
procedure as described in the subclauses 6.1.3.9.1 and 6.1.3.9.2. 



6.1.3.9.1 



MBMS context deactivation initiated by the network 



In order to request an MBMS context deactivation, the network sends a DEACTIVATE PDF CONTEXT REQUEST 
message to the MS, enters the state MBMS -INACTIVE-FENDING and starts timer T3395. The message contains the 
transaction identifier (TI) in use for the MBMS context to be deactivated and a cause code that typically indicates one 
of the following causes: 

# 36: regular deactivation; 

# 38: network failure; 

# 47: multicast group membership time-out. 

The MS shall reply with a DEACTIVATE FDF CONTEXT ACCEPT message and enter the state PDF-INACTIVE. 
Upon receipt of the DEACTIVATE PDF CONTEXT ACCEPT message, the network shall stop the timer T3395 and 
enter the state PDF-INACTIVE. 

6.1.3.9.2 Abnormal cases 

The following abnormal cases can be identified: 
a) Expiry of timers: 
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On the first expiry of the timer T3395, the network shall resend the message DEACTIVATE PDP 
CONTEXT REQUEST and shall reset and restart the timer T3395. This retransmission is repeated, i.e. on the 
fifth expiry of the timer T3395, the network shall erase the MBMS context related data for that MS. 



MS Network 

DEACTIVATE PDP CONTEXT REQUEST 



DEACTIVATE PDP CONTEXT ACCEPT 



Start T3395 



-► Stop T3395 



Figure 6.11/3GPP TS 24.008: MBMS context deactivation procedure 



6.1 .3.10 MBMS protocol configuration options 

The MS and the GGSN may communicate parameters related to the MBMS bearer by means of the MBMS protocol 
configuration options information element when activating or deactivating an MBMS context. For example, such 
parameters can be used to convey information between the MS and the GGSN. 

The MBMS protocol configuration options information element is transparent to the SGSN. 



6.1.3.11 



Handling of APN based congestion control 



The network may detect and start performing the APN based congestion control when one or more APN congestion 
criteria as specified in 3GPP TS 23.060 [74] are met. The network may store an APN congestion back-off time on a per 
MS and congested APN basis and reject any subsequent PDP context activation request, secondary PDP context 
activation request or PDP context modification request from the MS targeted towards the congested APN before the 
APN congestion back-off time for the congested APN elapses. 



6.2 



void 



6.3 Coordination between SIVI and GIVIIVI for supporting ISR 

The MS with its TIN set as "RAT-related TMSI" for which ISR is activated shall change its TIN to "P-TMSI" to locally 
deactivate ISR: 

upon modification of any PDP context which was activated before the ISR is activated in the MS; 

upon deactivation of the last PDP context in the MS; 

at the time when the MS changes from A/Gb mode or lu mode to S 1 mode, if any PDP context activated after the 
ISR was activated in the MS exists; or 

upon deactivation of last non-emergency PDP context in the MS, if the MS has only a PDN connection for 
emergency bearer services remaining. 

ISR remains activated on the network side in the above cases. 



6.4 IVISISDN notification procedure 



The MSISDN notification procedure allows the MS to query the network for its MSISDN for the purpose of user 
information. In order to request the MSISDN, the MS shall encode the protocol configuration options information 
element (subclause 10.5.6.3) in the MS to network direction to indicate MSISDN query. The network shall then provide 
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the MSISDN, if available, in the protocol configuration options information element in the network to MS direction. 
Querying the network and handling of the provided MSISDN by the MS is implementation dependent, in a similar way 
to the USSD notification or appHcation mode defined in 3GPP TS 23.090 [132]. 

NOTE: The MS might store the provided MSISDN in the corresponding USIM file (see 3GPP TS 31.102 [112] 
subclause 4.2.26) and such an MS could check this USIM file to determine whether to query the network. 

The network shall provide only one MSISDN. As a result, a provided MSISDN shall supercede any MSISDN that was 
previously provided in the protocol configuration options information element. The MSISDN provided is for user 
information only, and the MS shall not use the MSISDN in any NAS signalling procedure. If the MSISDN is stored in 
the ME, the ME shall retain the MSISDN at power off. The MSISDN stored in the ME, if any, can only be used if the 
IMSI from the USIM matches the IMSI stored in non-volatile memory, else the MS shall delete the MSISDN. 



7 Examples of structured procedures 

See 3GPPTS 23.108 [9a]. 

8 Handling of unknown, unforeseen, and erroneous 
protocol data 

8.1 General 

The procedures specified in 3GPP TS 24.008 and call-related supplementary service handling in 3GPP TS 24.010 [21] 
apply to those messages which pass the checks described in this subclause. 

This subclause also specifies procedures for the handling of unknown, unforeseen, and erroneous protocol data by the 
receiving entity. These procedures are called "error handling procedures", but in addition to providing recovery 
mechanisms for error situations they define a compatibility mechanism for future extensions of the protocols. 

Error handling concerning the value part of the Facility IE and of the SS Version Indicator IE are not in the scope of the 
present document. It is defined in 3GPP TS 24.010 [21] and the 3GPP TS 24.08x series. 

Sub subclauses 8.1 to 8.8 shall be applied in order of precedence. 

Most error handling procedures are mandatory for the mobile station. 

Detailed error handling procedures in the network are implementation dependent and may vary from PLMN to PLMN. 
However, when extensions of this protocol are developed, networks will be assumed to have the error handling that is 
indicated in this subclause as mandatory ("shall") and that is indicated as strongly recommended ("should"). 
Subclauses 8.2, 8.3, 8.4, 8.5 and 8.7.2 do not apply to the error handling in the network applied to the receipt of initial 
layer 3 message: If the network diagnoses an error described in one of these subclauses in the initial layer 3 message 
received from the mobile station, it shall either: 

try to recognize the classmark and then take further implementation dependent actions; or 

release the RR-connection. 

Also, the error handling of the network is only considered as mandatory or strongly recommended when certain 
thresholds for errors are not reached during a dedicated connection. 

For definition of semantical and syntactical errors see 3GPP TS 24.007 [20], subclause 1 1.4.2. 



8.2 Message too short 



When a message is received that is too short to contain a complete message type information element, that message 
shall be ignored, cf. 3GPP TS 24.007 [20]. 
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8.3 Unknown or unforeseen transaction identifier 
8.3.1 Call Control 

The mobile station and the network shall ignore a Call Control message received with TI EXT bit = 0. Otherwise, if the 
TI EXT bit =1 or no extension is used, the behaviour described below shall be followed. 

The mobile station and network shall reject a SETUP, EMERGENCY SETUP or START CC message received with 
octet 1 part of the TI value coded as " 111 " by sending RELEASE COMPLETE with cause #8 1 "Invalid transaction 
identifier value" The TI value in RELEASE COMPLETE shall be the complete TI value including the extension octet 
from the message that caused the rejection. 

Any message other than SETUP, EMERGENCY SETUP or START CC received with octet 1 part of the TI value 
coded as "111" shall be ignored. 

For a call control message received with octet 1 part of the TI value not coded as "111", the following procedures shall 
apply: 

a) For a network that does not support the "Network initiated MO call" option and for all mobile stations: 

Whenever any call control message except EMERGENCY SETUP, SETUP or RELEASE COMPLETE is 
received specifying a transaction identifier which is not recognized as relating to an active call or to a call in 
progress, the receiving entity shall send a RELEASE COMPLETE message with cause #81 "invalid transaction 
identifier value" using the received transaction identifier value and remain in the Null state. 

For a network that does support the "Network initiated MO call" option $(CCBS)$: 

Whenever any call control message except EMERGENCY SETUP, SETUP, START CC or RELEASE 
COMPLETE is received specifying a transaction identifier which is not recognized as relating to an active call or 
to a call in progress, the receiving entity shall send a RELEASE COMPLETE message with cause #81 "invalid 
transaction identifier value" using the received transaction identifier value and remain in the Null state. 

b) When a RELEASE COMPLETE message is received specifying a transaction identifier which is not recognized 
as relating to an active call or to a call in progress, the MM connection associated with that transaction identifier 
shall be released. 

c) For a network that does not support the "Network initiated MO call" option and for all mobile stations: 

When an EMERGENCY SETUP or, a SETUP message is received specifying a transaction identifier which is 
not recognized as relating to an active call or to a call in progress, and with a transaction identifier flag 
incorrectly set to " 1 ", this message shall be ignored. 

For a network that does support the "Network initiated MO call" option $(CCBS)$: 

When an EMERGENCY SETUP, a START CC or, a SETUP message is received specifying a transaction 
identifier which is not recognised as relating to an active call or to a call in progress, and with a transaction 
identifier flag incorrectly set to "1", this message shall be ignored. 

d) When a SETUP message is received by the mobile station specifying a transaction identifier which is recognized 
as relating to an active call or to a call in progress, this SETUP message shall be ignored. 

e) For a network that does not support the "Network initiated MO call" option: 

When an EMERGENCY SETUP message or a SETUP message is received by the network specifying a 
transaction identifier which is recognized as relating to an active call or to a call in progress, this message need 
not be treated and the network may perform other actions. 

For a network that does support the "Network initiated MO call" option $(CCBS)$: 

When an EMERGENCY SETUP message or a START CC message is received by the network specifying a 
transaction identifier which is recognised as relating to an active call or to a call in progress, this message need 
not be treated and the network may perform other actions. 
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The same applies to a SETUP message unless the transaction has been established by a START_CC message 
and the network is in the "recall present" state (N0.6). 

8.3.2 Session Management 

The mobile station and network shall ignore a session management message with TI EXT bit = 0. Otherwise, the 
following procedures shall apply: 

a) Whenever any session management message except ACTIVATE PDP CONTEXT REQUEST, ACTIVATE 
SECONDARY PDP CONTEXT REQUEST, or SM-STATUS is received by the network specifying a 
transaction identifier which is not recognized as relating to an active PDP context or MBMS context,or to a PDP 
context or MBMS context that is in the process of activation or deactivation, the network shall send a SM- 
STATUS message with cause #81 "invalid transaction identifier value" using the received transaction identifier 
value including the extension octet and remain in the PDP-INACTIVE state. 

b) Whenever any session management message except REQUEST PDP CONTEXT ACTIVATION, REQUEST 
SECONDARY PDP CONTEXT ACTIVATION, REQUEST MBMS CONTEXT ACTIVATION, or SM- 
STATUS is received by the MS specifying a transaction identifier which is not recognized as relating to an 
active context or to a context that is in the process of activation or deactivation, the MS shall send a SM- 
STATUS message with cause #81 "invalid transaction identifier value" using the received transaction identifier 
value including the extension octet and remain in the PDP-INACTIVE state. 

c) When a REQUEST PDP CONTEXT ACTIVATION message, REQUEST SECONDARY PDP CONTEXT 
ACTIVATION message or REQUEST MBMS CONTEXT ACTIVATION message is received by the MS with 
a transaction identifier flag set to "1", this message shall be ignored. 

d) When an ACTIVATE PDP CONTEXT REQUEST message is received by the network specifying a transaction 
identifier which is not recognized as relating to a PDP context that is in the process of activation, and with a 
transaction identifier flag set to "1", this message shall be ignored. 

e) Whenever an ACTIVATE PDP CONTEXT REQUEST or ACTIVATE SECONDARY PDP CONTEXT 
REQUEST message is received by the network specifying a transaction identifier relating to a PDP context or 
MBMS context not in state PDP-INACTIVE, the network shall deactivate the old PDP context or MBMS 
context relating to the received transaction identifier without notifying the MS. Furthermore, the network shall 
continue with the activation procedure of a new PDP context as indicated in the received message. Whenever an 
ACTIVATE MBMS CONTEXT REQUEST message is received by the network specifying a transaction 
identifier relating to an MBMS context not in state PDP-INACTIVE, the network shall deactivate the old MBMS 
context relating to the received transaction identifier without notifying the MS. Furthermore, the network shall 
continue with the activation procedure of a new MBMS context as indicated in the received message. 

f) Whenever a REQUEST PDP CONTEXT ACTIVATION message or REQUEST SECONDARY PDP 
CONTEXT ACTIVATION message is received by the MS specifying a transaction identifier relating to a PDP 
context or MBMS context not in state PDP-INACTIVE, the MS shall locally deactivate the old PDP context or 
MBMS context relating to the received transaction identifier. Furthermore, the MS shall continue with the 
activation procedure of a new PDP context as indicated in the received message. 

Whenever a REQUEST MBMS CONTEXT ACTIVATION message is received by the MS specifying a 
transaction identifier relating to a PDP context or MBMS context not in state PDP-INACTIVE, the MS shall 
locally deactivate the old PDP context or MBMS context relating to the received transaction identifier. 
Furthermore, the MS shall continue with the activation procedure of a new MBMS context as indicated in the 
received message. 

g) When an ACTIVATE SECONDARY PDP CONTEXT REQUEST message is received by the network 
specifying a transaction identifier which is not recognized as relating to a PDP context that is in the process of 
activation and with a transaction identifier flag set to "1", this message shall be ignored. 
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8.4 Unknown or unforeseen message type 

If a mobile station receives an RR, MM or CC message with message type not defined for the PD or not implemented 
by the receiver in unacknowledged mode, it shall ignore the message. 

If a mobile station receives an RR, MM or CC message with message type not defined for the PD or not implemented 
by the receiver in acknowledged mode, it shall return a status message (STATUS, MM STATUS depending on the 
protocol discriminator) with cause # 97 "message type non-existent or not implemented". 

If a mobile station receives a GMM message or SM message with message type not defined for the PD or not 
implemented by the receiver, it shall return a status message (GMM STATUS or SM STATUS depending on the 
protocol discriminator) with cause # 97 "message type non-existent or not implemented". 

If the network receives an MM message with message type not defined for the PD or not implemented by the receiver in 
a protocol state where reception of an unsolicited message with the given PD from the mobile station is not foreseen in 
the protocol, the network actions are implementation dependent. Otherwise, if the network receives a message with 
message type not defined for the PD or not implemented by the receiver, it shall ignore the message except that it 
should return a status message (STATUS, MM STATUS, GMM STATUS or SM STATUS depending on the protocol 
discriminator) with cause #97 "message type non-existent or not implemented". 

NOTE: A message type not defined for the PD in the given direction is regarded by the receiver as a message 
type not defined for the PD, see 3GPP TS 24.007 [20]. 

If the mobile station receives a message not compatible with the protocol state, the mobile station shall ignore the 
message except for the fact that, if an RR connection exists, it returns a status message (STATUS, MM STATUS 
depending on the protocol discriminator) with cause #98 "Message type not compatible with protocol state". When the 
message was a GMM message the GMM-STATUS message with cause #98 "Message type not compatible with 
protocol state" shall be returned. When the message was a SM message the SM-STATUS message with cause #98 
"Message type not compatible with protocol state" shall be returned. 

If the network receives a message not compatible with the protocol state, the network actions are implementation 
dependent. 

NOTE: The use by GMM and SM of unacknowledged LLC may lead to messages "not compatible with the 
protocol state". 

8.5 Non-semantical mandatory information element errors 

When on receipt of a message, 

an "imperative message part" error; or 

a "missing mandatory IE" error; 
is diagnosed or when a message containing: 

a syntactically incorrect mandatory IE; or 

an IE unknown in the message, but encoded as "comprehension required" (see 3GPP TS 24.007 [20]); or 

an out of sequence IE encoded as "comprehension required" (see 3GPP TS 24.007 [20]) is received, 

the mobile station shall proceed as follows: 

If the message is not one of the messages listed in subclauses 8.5.1, 8.5.2, 8.5.3, 8.5.4 and 8.5.5 a), b) or f), the 
mobile station shall ignore the message except for the fact that, if an RR connection exists, it shall return a status 
message (STATUS, MM STATUS depending on the protocol discriminator) with cause # 96 "Invalid mandatory 
information". If the message was a GMM message the GMM-STATUS message with cause #96 " Invalid 
mandatory information" shall be returned. If the message was an SM message the SM-STATUS message with 
cause # 96 "invalid mandatory information" shall be returned. 

the network shall proceed as follows: 
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When the message is not one of the messages listed in subclause 8.5.3 b), c), d) or e) and 8.5.5 a), c), d), e) or 
g), the network shall either: 

try to treat the message (the exact further actions are implementation dependent), or 

ignore the message except that it should return a status message (STATUS, or MM STATUS (depending 
on the protocol discriminator), GMM STATUS, or SM STATUS) with cause # 96 "Invalid mandatory 
information". 

8.5.1 Radio resource management 

See 3GPPTS 44.018 [84]. 

8.5.2 Mobility management 

No exceptional cases are described for mobility management messages. 

8.5.3 Call control 

a) If the message is a SETUP message, a RELEASE COMPLETE message with cause # 96 "invalid mandatory 
information" shall be returned. 

b) If the message is a DISCONNECT message, a RELEASE message shall be returned with cause value # 96 
"invalid mandatory information" and subclause 5.4. "call clearing" applies as normal. 

c) If the message is a RELEASE message, a RELEASE COMPLETE message shall be returned with cause value # 
96 "invalid mandatory information". 

d) If the message is a RELEASE COMPLETE message, it shall be treated as a normal RELEASE COMPLETE 

message. 

e) If the message is a HOLD REJECT or RETRIEVE REJECT message, it shall be treated as a normal HOLD 
REJECT or RETRIEVE REJECT message. 

f) If the message is a STATUS message and received by the network, a RELEASE COMPLETE message may be 
returned with cause value # 96 "invalid mandatory information". 

8.5.4 GMM mobility management 

No exceptional cases are described for mobility management messages. 

8.5.5 Session management 

a) If the message is a DEACTIVATE PDP CONTEXT REQUEST, a DEACTIVATE PDP CONTEXT ACCEPT 
message shall be returned. All resources allocated for that context shall be released. 

b) If the message is a REQUEST PDP CONTEXT ACTIVATION, a REQUEST PDP CONTEXT ACTIVATION 
REJECT message with cause # 96 "Invalid mandatory information" shall be returned. 

c) If the message is an ACTIVATE PDP CONTEXT REQUEST, an ACTIVATE PDP CONTEXT REJECT 
message with cause # 96 "Invalid mandatory information" shall be returned. 

d) If the message is an ACTIVATE SECONDARY PDP CONTEXT REQUEST, an ACTIVATE SECONDARY 
PDP CONTEXT REJECT message with cause # 96 "Invalid mandatory information" shall be returned. 

e) If the message is a MODIFY PDP CONTEXT REQUEST, a MODIFY PDP CONTEXT REJECT message with 
cause # 96 "Invalid mandatory information" shall be returned. 

f) If the message is a REQUEST MBMS CONTEXT ACTIVATION, a REQUEST MBMS CONTEXT 
ACTIVATION REJECT message with cause # 96 "Invalid mandatory information" shall be returned. 
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g) If the message is an ACTIVATE MBMS CONTEXT REQUEST, an ACTIVATE MBMS CONTEXT REJECT 
message with cause # 96 "Invalid mandatory information" shall be returned. 

h) If the message is a REQUEST SECONDARY PDP CONTEXT ACTIVATION, a REQUEST SECONDARY 
PDP CONTEXT ACTIVATION REJECT message with cause # 96 "InvaUd mandatory information" shall be 
returned. 

8.6 Unknown and unforeseen lEs in the non-imperative 
message part 

8.6.1 lEIs unknown in the message 

The MS shall ignore all lEs unknown in a message which are not encoded as "comprehension required" (see 
3GPP TS 24.007 [20]). 

The network shall take the same approach. 

8.6.2 Out of sequence lEs 

The MS shall ignore all out of sequence lEs in a message which are not encoded as "comprehension required" (see 
3GPP TS 24.007 [20]). 

The network should take the same approach. 

8.6.3 Repeated IBs 

If an information element with format T, TV, or TLV is repeated in a message in which repetition of the information 
element is not specified in clause 9 of the present document, only the contents of the information element appearing 
first shall be handled and all subsequent repetitions of the information element shall be ignored. When repetition of 
information elements is specified, only the contents of specified repeated information elements shall be handled. If the 
limit on repetition of information elements is exceeded, the contents of information elements appearing first up to the 
limit of repetitions shall be handled and all subsequent repetitions of the information element shall be ignored. 

The network should follow the same procedures. 

8.7 Non-imperative message part errors 

This category includes: 

syntactically incorrect optional lEs; 
conditional IE errors. 

8.7.1 Syntactically incorrect optional lEs 

The MS shall treat all optional lEs that are syntactically incorrect in a message as not present in the message. 
The network shall take the same approach. 

8.7.2 Conditional IE errors 

When the MS upon receipt of an RR, MM or CC message diagnoses a "missing conditional IE" error or an "unexpected 
conditional IE" error or when it receives an RR, MM or CC message containing at least one syntactically incorrect 
conditional IE, it shall ignore the message except for the fact that, if an RR connection exists, it shall return a status 
message (STATUS, or MM STATUS depending on the PD) with cause value # 100 "conditional IE error". 

When the MS upon receipt of a GMM or SM message diagnoses a "missing conditional IE" error or an "unexpected 
conditional IE" error or when it receives a GMM or SM message containing at least one syntactically incorrect 
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conditional IE, it shall ignore the message and it shall return a status message (GMM STATUS or SM STATUS 
depending on the PD) with cause value # 100 "conditional IE error". 

When the network receives a message and diagnose a "missing conditional IE" error or an "unexpected conditional IE" 
error or when it receives a message containing at least one syntactically incorrect conditional IE, the network shall 
either 

try to treat the message (the exact further actions are implementation dependent), or 

- ignore the message except that it should return a status message (STATUS, MM STATUS, GMM STATUS or 
SM STATUS depending on the protocol discriminator) with cause #100 "conditional IE error". 

8.8 Messages with semantically incorrect contents 

When a message with semantically incorrect contents is received, the foreseen reactions of the procedural part of 3GPP 
TS 24.008 (i.e. of clauses 3, 4, 5, 6) are performed. If however no such reactions are specified, the MS shall ignore the 
message except for the fact that, if an RR connection exists, it returns a status message (STATUS, or MM STATUS 
depending on the PD) with cause value # 95 "semantically incorrect message". If the message was a GMM message the 
GMM-STATUS message with cause #95 "semantically incorrect message" shall be returned. If the message was an SM 
message the SM-STATUS message with cause # 95 "semantically incorrect message" shall be returned. 

The network should follow the same procedure except that a status message is not normally transmitted. 

Semantic checking of the Facility information element value part (defined in 3GPP TS 24.080 [24]) is the subject of the 
technical specifications 3GPP TS 24.010 [21] and the 3GPP TS 24.08x series. 



9 IVIessage functional definitions and contents 

This clause defines the structure of the messages of those layer 3 protocols defined in 3GPP TS 24.008. These are 
standard L3 messages as defined in 3GPP TS 24.007 [20]. 

Each definition given in the present clause includes: 

a) a brief description of the message direction and use, including whether the message has: 

1. Local significance, i.e. relevant only on the originating or terminating access; 

2. Access significance, i.e. relevant in the originating and terminating access, but not in the network; 

3. Dual significance, i.e. relevant in either the originating or terminating access and in the network; or 

4. Global significance, i.e. relevant in the originating and terminating access and in the network. 

b) a table listing the information elements known in the message and their order of their appearance in the message. 
In messages for circuit-switched call control also a shift information element shall be considered as known even 
if not included in the table. All information elements that may be repeated are explicitly indicated. (V and LV 
formatted lEs, which compose the imperative part of the message, occur before T, TV, and TLV formatted lEs 
which compose the non-imperative part of the message, cf. 3GPP TS 24.007 [20].) In a (maximal) sequence of 
consecutive information elements with half octet length, the first information element with half octet length 
occupies bits 1 to 4 of octet N, the second bits 5 to 8 of octet N, the third bits 1 to 4 of octet Nh-1 etc. Such a 
sequence always has an even number of elements. 

For each information element the table indicates: 

1 . the information element identifier, in hexadecimal notation, if the IE has format T, TV, or TLV. Usually, 
there is a default lEI for an information element type; default lEIs of different IE types of the same protocol 
are different. If the lEI has half octet length, it is specified by a notation representing the lEI as a 
hexadecimal digit followed by a "-" (example: B-). 

NOTE 1: The same lEI may be used for different information element types in different messages of the same 
protocol. 
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NOTE 2: In the CC protocol the lEI of the locking shift and non-locking shift information elements is the same in 
all messages and is not used for any other information elements. 

2. the name of the information element (which may give an idea of the semantics of the element). The name of 
the information element (usually written in italics) followed by "IE" or "information element" is used in 
3GPP TS 24.008 as reference to the information element within a message. 

3. the name of the type of the information element (which indicates the coding of the value part of the IE), and 
generally, the referenced subclause of clause 10 of 3GPP TS 24.008 describing the value part of the 
information element. 

4. the presence requirement indication (M, C, or O) for the IE as defined in 3GPP TS 24.007 [20]. 

5. The format of the information element (T, V, TV, LV, TLV) as defined in 3GPP TS 24.007 [20]. 

6. The length of the information element (or permissible range of lengths), in octets, in the message, where "?" 
means that the maximum length of the IE is only constrained by link layer protocol, and in the case of the 
Facility IE by possible further conditions specified in 3GPP TS 24.010 [21]. This indication is non- 
normative. 

c.) subclauses specifying, where appropriate, conditions for lEs with presence requirement C or O in the relevant 
message which together with other conditions specified in 3GPP TS 24.008 define when the information 
elements shall be included or not, what non-presence of such lEs means, and - for lEs with presence requirement 
C - the static conditions for presence and/or non-presence of the lEs (see 3GPP TS 24.007 [20]). 

9.1 Messages for Radio Resources management 

See 3GPPTS 44.018 [84]. 

9.2 Messages for mobility management 

Table 9.2.1/3GPP TS 24.008 summarizes the messages for mobility management. 

Table 9.2.1/3GPP TS 24.008: Messages for mobility management 



Registration messages: 


Reference 


IMSI DETACH INDICATION 


9.2.12 


LOCATION UPDATING ACCEPT 


9.2.13 


LOCATION UPDATING REJECT 


9.2.14 


LOCATION UPDATING REQUEST 


9.2.15 


Security messages: 


Reference 


AUTHENTICATION REJECT 


9.2.1 


AUTHENTICATION REQUEST 


9.2.2 


AUTHENTICATION RESPONSE 


9.2.3 


AUTHENTICATION FAILURE 


9.2.3a 


IDENTITY REQUEST 


9.2.10 


IDENTITY RESPONSE 


9.2.11 


TMSI REALLOCATION COMMAND 


9.2.17 


TMSI REALLOCATION COMPLETE 


9.2.18 


Connection management messages: 


Reference 


CM SERVICE ACCEPT 


9.2.5 


CM SERVICE PROMPT 


9.2.5a 


CM SERVICE REJECT 


9.2.6 


CM SERVICE ABORT 


9.2.7 


CM SERVICE REQUEST 


9.2.9 


CM RE-ESTABLISHMENT REQUEST 


9.2.4 


ABORT 


9.2.8 


Miscellaneous message: 


Reference 


MM INFORMATION 


9.2.15a 


MM STATUS 


9.2.16 


MM NULL 


9.2.19 
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9.2.1 Authentication reject 



This message is sent by the network to the mobile station to indicate that authentication has failed (and that the 
receiving mobile station shall abort all activities). See table 9.2.2/3GPP TS 24.008. 

Message type: AUTHENTICATION REJECT 

Significance: dual 

Direction: network to mobile station 

Table 9.2.2/3GPP TS 24.008: AUTHENTICATION REJECT message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Authentication Reject 
message type 


Message type 
10.4 


M 


V 


1 



9.2.2 Autlnentication request 



This message is sent by the network to the mobile station to initiate authentication of the mobile station identity. See 
table 9.2.3/3GPP TS 24.008. 

Message type: AUTHENTICATION REQUEST 

Significance: dual 

Direction: network to mobile station 

Table 9.2.3/3GPP TS 24.008: AUTHENTICATION REQUEST message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Authentication Request 
message type 


Message type 
10.4 


M 


V 


1 




Ciphering key sequence 
number 


Ciphering key sequence 

number 

10.5.1.2 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 




Authentication 
parameter RAND (UMTS 
challenge or GSM challenge) 


Auth. parameter RAND 
10.5.3.1 


M 


V 


16 


20 


Authentication 
Parameter AUTN 


Auth. parameter AUTN 
10.5.3.1.1 





TLV 


18 



9.2.2.1 



Authentication Parameter AUTN 



This IE shall be present if and only if the authentication challenge is a UMTS authentication challenge. The presence or 
absence of this IE defines- in the case of its absence- a GSM authentication challenge or- in the case of its presence- a 
UMTS authentication challenge. 

The MS shall ignore the IE if a SIM is inserted in the MS. 

In UMTS, the MS shall reject the AUTHENTICATION REQUEST message as specified in subclause 4.3.2.5.1 if this 
IE is not present and a USIM is inserted in the MS. 
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9.2.3 Authentication response 



This message is sent by the mobile station to the network to deliver a calculated response to the network. See 
table 9.2.4/3GPP TS 24.008. 

Message type: AUTHENTICATION RESPONSE 

Significance: dual 

Direction: mobile station to network 

Table 9.2.4/3GPP TS 24.008: AUTHENTICATION RESPONSE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Authentication Response 
message type 


Message type 
10.4 


M 


V 


1 




Authentication Response 
parameter 


Auth. Response parameter 
10.5.3.2 


M 


V 


4 


21 


Authentication Response 
Parameter (extension) 


Auth. Response parameter 
10.5.3.2.1 





TLV 


3-14 



9.2.3.1 



Authentication Response Parameter 



This IE contains the SRES, if it was a GSM authentication challenge, or the RES (all or just the 4 most significant 
octets of) if it was a UMTS authentication challenge (see also subclause 9.2.3.2). 



9.2.3.2 



Authentication Response Parameter (extension) 



This IE shall be included if and only if the authentication challenge was a UMTS authentication challenge and the RES 
parameter is greater than 4 octets in length. It shall contain the least significant remaining bits of the RES (the four most 
significant octets shall be sent in the Authentication Response Parameter IE (see subclause 9.2.3.1)) 

This IE shall not be included if a SIM is inserted in the MS. 

9.2.3a Authentication Failure 

This message is sent by the mobile station to the network to indicate that authentication of the network has failed. See 
table 9.2.4a/3GPP TS 24.008. 

Message type: AUTHENTICATION FAILURE 

Significance: dual 

Direction: mobile station to network 

Table 9.2.4a/3GPP TS 24.008: AUTHENTICATION FAILURE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Authentication Failure 
Message type 


Message type 
10.4 


M 


V 


1 




Reject Cause 


Reject Cause 
10.5.3.6 


M 


V 


1 


22 


Authentication Failure parameter 


Authentication Failure parameter 
10.5.3.2.2 





TLV 


16 
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9.2.3a.1 Authentication Failure parameter 

This IE shall be sent if and only if the reject cause was "Synch failure". It shall include the response to the 
authentication challenge from the USIM, which is made up of the AUTS parameter (see 3GPP TS 33.102 [5a]). 

9.2.4 CM Re-establishment request 

This message is sent by the mobile station to the network to request re-establishment of a connection if the previous one 
has failed. See table 9.2.5/3GPP TS 24.008. 

Message type: CM RE-ESTABLISHMENT REQUEST 

Significance: dual 

Direction: mobile station to network 

Table 9.2.5/3GPP TS 24.008: CM RE-ESTABLISHMENT REQUEST message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




IVIobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




CIVI Re-Establistiment 
Request message type 


Message type 
10.4 


M 


V 


1 




Ciphering l<ey sequence 
number 


Ciphering key sequence 

number 

10.5.1.2 


M 


V 


y2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


y2 




IVIobile station 
classmark 


Mobile station 
classmark 2 
10.5.1.6 


M 


LV 


4 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


2-9 


13 


Location area 
identification 


Location area 

identification 

10.5.1.3 


C 


TV 


6 


D- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 



NOTE: In A/Gb mode, the maximum number of octets that can be transferred is 20. 



9.2.4.1 



Location area identification 



The location area identification information element shall appear when a TMSI is used as mobile identity, to render that 
mobile identity non-ambiguous. This is the LAI stored in the SIM/USIM. 

9.2.4.2 Mobile Station Classmark 

This IE shall include for multiband mobile station the Classmark 2 corresponding to the frequency band in use. 

9.2.4.3 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 



9.2.5 CM service accept 



This message is sent by the network to the mobile station to indicate that the requested service has been accepted. See 
table 9.2.6/3GPP TS 24.008. 
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Message type: CM SERVICE ACCEPT 

Significance: dual 

Direction: network to mobile station 



Table 9.2.6/3GPP TS 24.008: CM SERVICE ACCEPT message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




CM Service Accept 
message type 


Message type 
10.4 


M 


V 


1 



9.2.5a CM service prompt $(CCBS)$ 



A mobile station that does not support the "Network initiated MO call" option shall treat this message as a message with 
message type not defined for the PD. 

This message is sent by the network to the mobile station to request the mobile to establish a service for the specified 
CM protocol using the specified SAPI, e.g. circuit switched connection establishment on SAPI 0, supplementary 
services activation on SAPI 0, or short message transfer on SAPI 3. See Table 9.2.7/3GPP TS 24.008. 

Message type: CM SERVICE PROMPT 

Significance: dual 

Direction: network to mobile station 

Table 9.2.7/3GPP TS 24.008: CM SERVICE PROMPT message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




CM Service Prompt 
message type 


Message type 
10.4 


M 


V 


1 




PD and SAPI of CM 


PD and SAPI 
10.5.1.10a 


M 


V 


1 



9.2.6 CM service reject 



This message is sent by the network to the mobile station to indicate that the requested service cannot be provided. See 
table 9.2.8/3GPP TS 24.008. 

Message type: CM SERVICE REJECT 

Significance: dual 

Direction: network to mobile station 
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Table 9.2.8/3GPP TS 24.008: CM SERVICE REJECT message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




CM Service Reject 
message type 


Message type 
10.4 


M 


V 


1 




Reject cause 


Reject cause 
10.5.3.6 


M 


V 


1 


36 


T3246 value 


MM timer 
10.5.3.16 





TLV 


3 



9.2.6.1 T3246 value 

This IE may be included when the CS domain NAS level mobility management congestion control is active. 

9.2.7 CM service abort 

This message is sent by the mobile station to the network to request the abortion of the first MM connection 
establishment in progress and the release of the RR connection. See table 9.2.9/3GPP TS 24.008. 

Message type: CM SERVICE ABORT 

Significance: dual 

Direction: mobile station to network 

Table 9.2.9/3GPP TS 24.008: CM SERVICE ABORT message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




CM Service Abort 
message type 


Message type 
10.4 


M 


V 


1 



9.2.8 Abort 

This message is sent by the network to the mobile station to initiate the abortion of all MM connections and to indicate 
the reason for the abortion. See table 9.2.10/3GPP TS 24.008. 

Message type: ABORT 

Significance: dual 

Direction: network to mobile station 

Table 9.2.1 0/3GPP TS 24.008: ABORT message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Abort 
message type 


Message type 
10.4 


M 


V 


1 




Reject cause 


Reject cause 
10.5.3.6 


M 


V 


1 
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9.2.9 CM service request 

This message is sent by the mobile station to the network to request a service for the connection management sublayer 
entities, e.g. circuit switched connection establishment, supplementary services activation, short message transfer, 
location services. See table 9.2.11/3GPP TS 24.008. 

Message type: CM SERVICE REQUEST 

Significance: dual 

Direction: mobile station to network 

Table 9.2.1 1/3GPP TS 24.008: CM SERVICE REQUEST message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




IVIobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


yi 




CIVI Service Request 
message type 


Message type 
10.4 


M 


V 


1 




CIVI service type 


CM service type 
10.5.3.3 


M 


V 


yi 




Ciphering key sequence 
number 


Ciphering key sequence 

number 

10.5.1.2 


M 


V 


V2 




IVIobile station 
classmark 


Mobile station 
classmark 2 
10.5.1.6 


M 


LV 


4 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


2-9 


8- 


Priority 


Priority Level 
10.5.1.11 





TV 


1 


C- 


Additional update parameters 


Additional update parameters 
10.5.3.14 





TV 


1 


D- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 



9.2.9.1 Mobile Station Classmark 

This IE shall include for multiband mobile station the Classmark 2 corresponding to the frequency band in use. 

9.2.9.2 Priority 

May be included by mobile station supporting eMLPP to indicate the priority requested. 
This information element is only meaningful when the CM service type is: 

Mobile originating call establishment; 

Emergency call establishment; 

Voice group call establishment; 

Voice broadcast call establishment. 

9.2.9.3 Additional update parameters 

The MS shall include this IE during CS fallback for a mobile originating call (see subclause 4.5. 1. 1). 

9.2.9.4 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 
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9.2.10 Identity request 



This message is sent by the network to the mobile station to request a mobile station to submit the specified identity to 
the network. See table 9.2.12/3GPP TS 24.008. 

Message type: IDENTITY REQUEST 

Significance: dual 

Direction: network to mobile station 

Table 9.2.1 2/3GPP TS 24.008: IDENTITY REQUEST message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Identity Request 
message type 


Message type 
10.4 


M 


V 


1 




Identity type 


Identity type 
10.5.3.4 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 



9.2.1 1 Identity response 

This message is sent by the mobile station to the network in response to an IDENTITY REQUEST message providing 
the requested identity. See table 9.2.13/3GPP TS 24.008. 

Message type: IDENTITY RESPONSE 

Significance: dual 

Direction: mobile station to network 

Table 9.2.1 3/3GPP TS 24.008: IDENTITY RESPONSE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Identity Response 
message type 


Message type 
10.4 


M 


V 


1 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


2-10 



9.2.12 IMSI detach indication 



This message is sent by the mobile station to the network to set a deactivation indication in the network. See 
table 9.2.14/3GPP TS 24.008. 

Message type: IMSI DETACH INDICATION 

Significance: dual 

Direction: mobile station to network 
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Table 9.2.1 4/3GPP TS 24.008: IMSI DETACH INDICATION message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




IVIobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




IMSI Detach Indication 
message type 


Message type 
10.4 


M 


V 


1 




Mobile station 
classmark 


Mobile station 
classmark 1 
10.5.1.5 


M 


V 


1 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


2-9 



9.2.1 2.1 Mobile Station Classmark 

This IE shall include for multiband mobile station the Classmark 1 corresponding to the frequency band in use. 

9.2.13 Location updating accept 

This message is sent by the network to the mobile station to indicate that updating or IMSI attach in the network has 
been completed. See table 9.2.15/3GPP TS 24.008. 

Message type: LOCATION UPDATING ACCEPT 

Significance: dual 

Direction: network to mobile station 

Table 9.2.1 5/3GPP TS 24.008: LOCATION UPDATING ACCEPT message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


'h 




Location Updating 
Accept message type 


Message type 
10.4 


M 


V 


1 




Location area 
identification 


Location area 

identification 

10.5.1.3 


M 


V 


5 


17 


Mobile identity 


Mobile identity 
10.5.1.4 





TLV 


3-10 


A1 


Follow on proceed 


Follow on proceed 
10.5.3.7 





T 


1 


A2 


CTS permission 


CTS permission 
10.5.3.10 





T 


1 


4A 


Equivalent PLMNs 


PLMN list 
10.5.1.13 





TLV 


5-47 


34 


Emergency Number List 


Emergency Number List 
10.5.3.13 





TLV 


5-50 


35 


Per MS 1321 2 


GPRS Timer 3 
10.5.7.4a 





TLV 


3 



9.2.13.1 Follow on proceed 

Ths, follow on proceed information element appears if the network wishes to indicate that the mobile station may 
attempt an MM connection establishment using the same RR connection. 
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9.2.13.2 CTS permission 

The CTS permission information element appears if the network wishes to allow the mobile station to use GSM- 
Cordless Telephony System in the Location Area. 

9.2.13.3 Equivalent PLMNs 

The Equivalent PLMNs information element is included if the network wants to inform the mobile station of equivalent 
PLMNs. 

9.2.13.4 Emergency Number List 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicates a list of emergency numbers valid 
within the same MCC as in the cell on which this IE is received. 



9.2.13.5 



Perl\/IST3212 



This IE may be sent by the network to provide the MS with a periodic LAU timer that may be different to the broadcast 
value, e.g. to lengthen the timer. 

9.2.14 Location updating reject 

This message is sent by the network to the mobile station to indicate that updating or IMSI attach has failed. See 
table 9.2.16/3GPP TS 24.008. 

Message type: LOCATION UPDATING REJECT 

Significance: dual 

Direction: network to mobile station 

Table 9.2.16/3GPP TS 24.008: LOCATION UPDATING REJECT message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Location Updating 
Reject message type 


Message type 
10.4 


M 


V 


1 




Reject cause 


Reject cause 
10.5.3.6 


M 


V 


1 


36 


T3246 value 


MM timer 
10.5.3.16 





TLV 


3 



9.2.14.1 T3246 value 

This IE may be included when the CS domain NAS level mobility management congestion control is active. 

9.2.15 Location updating request 

This message is sent by the mobile station to the network either to request update of its location file (normal updating or 
periodic updating) or to request IMSI attach. See table 9.2.17/3GPP TS 24.008. 

Message type: LOCATION UPDATING REQUEST 

Significance: dual 

Direction: mobile station to network 
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Table 9.2.1 7/3GPP TS 24.008: LOCATION UPDATING REQUEST message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Location Updating 
Request message type 


Message type 
10.4 


M 


V 


1 




Location updating type 


Location updating type 
10.5.3.5 


M 


V 


1/2 




Ciphering key sequence 
number 


Ciphering key sequence 

number 

10.5.1.2 


M 


V 


1/2 




Location area 
identification 


Location area 

identification 

10.5.1.3 


M 


V 


5 




Mobile station 
classmark 


Mobile station 
classmark 1 
10.5.1.5 


M 


V 


1 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


2-9 


33 


Mobile station 
classmark for UMTS 


Mobile station 
classmark 2 
10.5.1.6 





TLV 


5 


C- 


Additional update parameters 


Additional update parameters 
10.5.3.14 





TV 


1 


D- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 


E- 


MS network feature support 


MS network feature support 
10.5.1.15 





TV 


1 



NOTE: In A/Gb mode, the maximum number of octets that can be transferred is 20. 

9.2.15.1 Location area identification 

The location area identification stored in the SIM/USIM is used. 

9.2.1 5.2 Mobile Station Classmark 

This IE shall include for multiband MS the Classmark 1 corresponding to the frequency band in use. 



9.2.15.3 



Mobile Station Classmark for lu mode 



This IE shall be included when the mobile station is in lu mode network. The IE shall not be included when the mobile 
station is in A/Gb mode network. 

9.2.15.4 Additional update parameters 

The MS shall include this IE if, during CS fallback for a CS call, the MS determines that it has to perform location 
updating when it enters a GERAN or UTRAN cell (see subclauses 4.5.1.1 and 4.5.1.3.4). 

9.2.15.5 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.2.1 5.6 MS network feature support 

This IE shall be included if the MS supports extended periodic timer T3212 and the Additional update parameters IE is 
not included. 
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9.2.15a MM information 

This message is sent by the network to the mobile station to provide the mobile station with subscriber specific 
information. See table 9.2.18/3GPP TS 24.008. 

Message type: MM INFORMATION 

Significance: dual 

Direction: network to mobile station 

Table 9.2.1 8/3GPP TS 24.008 MM INFORMATION message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




MM Information 
message type 


Message type 
10.4 


M 


V 


1 


43 


Full name for network 


Network Name 
10.5.3.5a 





TLV 


3-? 


45 


Short name for network 


Network Name 
10.5.3.5a 





TLV 


3-? 


46 


Local time zone 


Time Zone 
10.5.3.8 





TV 


2 


47 


Universal time and local time 
zone 


Time Zone and Time 
10.5.3.9 





TV 


8 


48 


LSA Identity 


LSA Identifier 
10.5.3.11 





TLV 


2-5 


49 


Network Daylight Saving Time 


Daylight Saving Time 
10.5.3.12 





TLV 


3 



9.2.1 5a.1 Full name for network 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicate the "full length name of the 
network" that the network wishes the mobile station to associate with the MCC and MNC contained in the Location 
Area Identification of the cell to which the mobile station sent its Channel Request message. 

9.2.1 5a.2 Short name for network 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicate the "abbreviated name of the 
network" that the network wishes the mobile station to associate with the MCC and MNC contained in the Location 
Area Identification of the cell to which the mobile station sent its Channel Request message. 

9.2.1 5a.3 Local time zone 

This IE may be sent by the network. The mobile station should assume that this time zone applies to the Location Area 
of the cell to which the Channel Request message was sent. 

If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE 
Network Daylight Saving Time. 

9.2.1 5a.4 Universal time and local time zone 

This IE may be sent by the network. The mobile station should assume that this time zone applies to the Location Area 
of the cell to which the Channel Request message was sent. The mobile station shall not assume that the time 
information is accurate. 

If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE 
Network Daylight Saving Time. 
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9.2.1 5a.5 LSA Identity 

This IE may be sent by the network. The contents of this IE indicate the LSA identity of the serving cell. 

9.2.1 5a.6 Network Daylight Saving Time 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicates the value that has been used to 
adjust the local time zone. 

9.2.16 MM Status 

This message is sent by the mobile station or the network at any time to report certain error conditions listed in clause i 
See table 9.2.19/3GPP TS 24.008. 

Message type: MM STATUS 

Significance: local 

Direction: both 

Table 9.2.1 9/3GPP TS 24.008: MM STATUS message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




MM Status message 
type 


Message type 
10.4 


M 


V 


1 




Reject cause 


Reject cause 
10.5.3.6 


M 


V 


1 



9.2.17 IMS! reallocation command 

This message is sent by the network to the mobile station to reallocate or delete a TMSI. See table 9.2.20/3GPP TS 
24.008. 

Message type: TMSI REALLOCATION COMMAND 

Significance: dual 

Direction: network to mobile station 

Table 9.2.20/3GPP TS 24.008: TMSI REALLOCATION COMMAND message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




TMSI Reallocation 
Command message type 


Message type 
10.4 


M 


V 


1 




Location area 
identification 


Location area 

identification 

10.5.1.3 


M 


V 


5 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


2-9 
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9.2.18 TMSI reallocation complete 

This message is sent by the mobile station to the network to indicate that reallocation or deletion of a TMSI has taken 
place. See table 9.2.21/3GPP TS 24.008. 

Message type: TMSI REALLOCATION COMPLETE 

Significance: dual 

Direction: mobile station to network 

Table 9.2.21/3GPP TS 24.008: TMSI REALLOCATION COMPLETE message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




TMSI Reallocation 
Complete message type 


Message type 
10.4 


M 


V 


1 



9.2.19 MM Null 

This message is sent in mobile to network direction. 

This message is not used on the radio interface. When received by the network it shall be ignored. 

The introduction of this message solves interworking issues. 

Message type: MM NULL 

Table 9.2.22/3GPP TS 24.008 MM NULL message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




MM Null message 
type 


Message type 
10.4 


M 


V 


1 
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9.3 Messages for circuit-switched call control 

Table 9.54/3GPP TS 24.008 summarizes the messages for circuit-switched call control. 

Table 9.54/3GPP TS 24.008: Messages for circuit-mode connections call control. 



Call establishment messages: 


Reference 


ALERTING 


9.3.1 


CALL CONFIRMED 1) 


9.3.2 


CALL PROCEEDING 


9.3.3 


CONNECT 


9.3.5 


CONNECT ACKNOWLEDGE 


9.3.6 


EMERGENCY SETUP 1) 


9.3.8 


PROGRESS 


9.3.17 


CC-ESTABLISHMENT 


9.3.17a 


CC-ESTABLISHMENT CONFIRMED 


9.3.17b 


START CC 


9.3.23a 


SETUP 


9.3.23 


Call information phase messages: 


Reference 


MODIFY 1) 


9.3.13 


MODIFY COMPLETE 1) 


9.3.14 


MODIFY REJECT 1) 


9.3.15 


USER INFORMATION 


9.3.31 


Call clearing messages: 


Reference 


DISCONNECT 


9.3.7 


RELEASE 


9.3.18 


RELEASE COMPLETE 


9.3.19 


Messages for supplementary service control 


Reference 


FACILITY 


9.3.9 


H0LD1) 


9.3.10 


HOLD ACKNOWLEDGE 1) 


9.3.11 


HOLD REJECT 1) 


9.3.12 


RETRIEVE 1) 


9.3.20 


RETRIEVE ACKNOWLEDGE 1) 


9.3.21 


RETRIEVE REJECT 1) 


9.3.22 


Miscellaneous messages 


Reference 


CONGESTION CONTROL 


9.3.4 


NOTIFY 


9.3.16 


START DTMF 1 ) 


9.3.24 


START DTMF ACKNOWLEDGE 1) 


9.3.25 


START DTMF REJECT 1) 


9.3.26 


STATUS 


9.3.27 


STATUS ENQUIRY 


9.3.28 


STOP DTMF 1) 


9.3.29 


STOP DTMF ACKNOWLEDGE 1) 


9.3.30 



NOTE: Not supported by Blue Book ITU-T Rec. Q.93 1 . 

9.3.1 Alerting 

9.3.1 .1 Alerting (network to mobile station direction) 

This message is sent by the network to the calling mobile station to indicate that the called user alerting has been 
initiated. 

See table 9.55/3GPP TS 24.008. 

Message type: ALERTING 

Significance: global 

Direction: network to mobile station 
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Table 9.55/3GPP TS 24.008: ALERTING message content (network to mobile station direction) 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Alerting 
message type 


IVIessage type 
10.4 


M 


V 


1 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


IE 


Progress indicator 


Progress indicator 
10.5.4.21 





TLV 


4 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 



9.3.1.1.1 Facility 

This information element may be used for functional operation of supplementary services. 

9.3.1.1.2 Progress indicator 

This information element may be included by the network: 

in order to pass information about the call in progress, e.g., in the event of interworking; 

to make the mobile station attach the user connection for speech; and/or 

to make a mobile station supporting multimedia CAT during the alerting phase of a mobile originated 
multimedia call establishment attach the user connection and setup an H.324 call. 



9.3.1.1.3 



User-user 



This information element may be included by the network if the called remote user included a user-user information 
element in the ALERTING message. 



9.3.1.2 



Alerting (mobile station to network direction) 



This message is sent by the called mobile station to the network, to indicate that the called user alerting has been 
initiated. 

See table 9.55a/3GPP TS 24.008. 

Message type: ALERTING 

Significance: global 

Direction: mobile station to network 
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Table 9.55a/3GPP TS 24.008: ALERTING message content (mobile station to network direction) 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Alerting 
message type 


Message type 
10.4 


M 


V 


1 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 


7F 


SS version 


SS version indicator 
10.5.4.24 





TLV 


2-3 



9.3.1.2.1 Facility 

This information element may be used for functional operation of supplementary services. 

9.3.1.2.2 User-user 

This information element may be included when the called mobile station wants to return information to the calling 
remote user. 

9.3.1.2.3 SS version 

This information element shall not be included if the/flc;7/f>' information element is not present in this message. 

This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 

9.3.2 Call confirmed 

This message is sent by the called mobile station to confirm an incoming call request. 
See table 9.56/3GPP TS 24.008. 

Message type: CALL CONFIRMED 

Significance: local 

Direction: mobile station to network 
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Table 9.56/3GPP TS 24.008: CALL CONFIRMED message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Call confirmed 
message type 


Message type 
10.4 


M 


V 


1 


D- 


Repeat Indicator 


Repeat Indicator 
10.5.4.22 


C 


TV 


1 


04 


Bearer capability 1 


Bearer capability 
10.5.4.5 





TLV 


3-16 


04 


Bearer capability 2 


Bearer capability 
10.5.4.5 





TLV 


3-16 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 


15 


CC Capabilities 


Call Control Capabilities 
10.5.4.5a 





TLV 


4 


2D 


Stream Identifier 


Stream Identifier 
10.5.4.28 





TLV 


3 


40 


Supported Codecs 


Supported Codec List 
10.5.4.32 





TLV 


5-n 



9.3.2.1 



Repeat indicator 



The repeat indicator information element shall be included if bearer capability 1 information element and bearer 
capability 2 IE are both included in the message. 



9.3.2.2 



Bearer capability 1 and bearer capability 2 



The bearer capability 1 information element shall be included if and only if at least one of the following six cases 
holds: 

the mobile station wishes another bearer capability than that given by the bearer capability 1 information 
element of the incoming SETUP message; 

the bearer capability 1 information element is missing or not fully specified in the SETUP message; 

the bearer capability 1 information element received in the SETUP message is accepted and the "radio channel 
requirement" of the mobile station is other than "full rate support only mobile station"; 

the bearer capability 1 information element received in the SETUP message indicates speech and is accepted 
and the mobile station supports CTM text telephony; 

the bearer capability 1 information element received in the SETUP message indicates speech and is accepted 
and the mobile station supports other codecs for GERAN than GSM speech version 1 ; 

the bearer capability 1 information element received in the SETUP message included the "fixed network user 
rate" parameter. 

When the bearer capability 1 information element is followed by the bearer capability 2 IE in the SETUP, the above 
rules apply to both bearer capability 1 IE and bearer capability 2 IE. Except those cases identified in 3GPP TS 
27.001 [36], if either bearer capability needs to be included, both shall be included. 

Furthermore, both bearer capability information elements may be present if the mobile station wishes to reverse the 
order of occurrence of the bearer capability information elements (which is referred to in the repeat indicator 
information element, see subclause 10.5.4.22) in cases identified in 3GPP TS 27.001 [36]. 

If the mobile station wishes to indicate capability for an alternative call mode, which can be entered during the call 
through in-call modification, this is indicated by adding a bearer capability information element (bearer capability 2 
information element, see subclause 5.3.6). 
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9.3.2.3 Cause 

This information element is included if the mobile station is compatible but the user is busy. 

9.3.2.4 CC Capabilities 

This information element may be included by the mobile station to indicate its call control capabilities. 

9.3.2.5 Stream Identifier 

This information element shall be included by the mobile station supporting multicall. 

9.3.2.6 Supported Codecs 

This information element shall be included for speech calls, if the mobile station supports UMTS radio access. 

9.3.3 Call proceeding 

This message is sent by the network to the calling mobile station to indicate that the requested call establishment 
information has been received, and no more call establishment information will be accepted. 

See table 9.57/3GPP TS 24.008. 

Message type: CALL PROCEEDING 

Significance: local 

Direction: network to mobile station 

Table 9.57/3GPP TS 24.008: CALL PROCEEDING message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Call proceeding 
message type 


IVIessage type 
10.4 


M 


V 


1 


D- 


Repeat Indicator 


Repeat Indicator 
10.5.4.22 


C 


TV 


1 


04 


Bearer capability 1 


Bearer capability 
10.5.4.5 





TLV 


3-16 


04 


Bearer capability 2 


Bearer capability 
10.5.4.5 





TLV 


3-16 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


IE 


Progress indicator 


Progress indicator 
10.5.4.21 





TLV 


4 


8- 


Priority granted 


Priority Level 
10.5.1.11 





TV 


1 


2F 


Network Call Control 
Capabilities 


Network Call Control cap. 
10.5.4.29 





TLV 


3 



9.3.3.1 



Repeat indicator 



This information element is included if and only if bearer capability 1 IE and bearer capability 2 IE are both contained 
in the message. 
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9.3.3.2 



Bearer capability 1 and bearer capability 2 



The bearer capability 1 information element shall be included if the network has to specify at least one of the 
negotiable parameters described in 3GPP TS 27.001 [36], or if the bearer capability 1 information element received in 
the SETUP message included the "fixed network user rate" parameter. 

When the bearer capability 1 information element is followed by the bearer capability 2 IE in the SETUP, the above 
rule applies to both bearer capability 1 IE and bearer capability 2 IE. Except those cases identified in 
3GPP TS 27.001 [36], if either bearer capability needs to be included, both shall be included. 

9.3.3.3 Facility 

This information element may be used for functional operation of supplementary services. 

9.3.3.4 Progress Indicator 

This information element may be included: 

in order to pass information about the call in progress e.g. in the event of interworking; and/or 
to make the MS attach the user connection for speech. 

9.3.3.5 Priority granted 

The priority field is provided by the network in the case that eMLPP is supported. 

9.3.3.6 Network Call Control Capabilities 

This information shall be included by the network to indicate its call control capabilities if the network supports 
multicall.and there are no other ongoing calls to the MS. 

9.3.4 Congestion control 

This message is sent by the network to indicate the establishment or termination of flow control on the transmission of 
USER INFORMATION messages. 

See table 9.58/3GPP TS 24.008. 

Message type: CONGESTION CONTROL 

Significance: local (note) 

Direction: network to mobile station 

Table 9.58/3GPP TS 24.008: CONGESTION CONTROL message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Congestion control 
message type 


IVIessage type 
10.4 


M 


V 


1 




Congestion level 


Congestion level 
10.5.4.12 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 



NOTE: This message has local significance, but may carry information of global significance. 
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9.3.4.1 



Cause 



This information element is included if the user to user information has been discarded as a result of the congestion 
situation. 

9.3.5 Connect 

9.3.5.1 Connect (network to mobile station direction) 

This message is sent by the network to the calling mobile station to indicate call acceptance by the called user. 
See table 9.59/3GPP TS 24.008. 

Message type: CONNECT 

Significance: global 

Direction: network to mobile station 

Table 9.59/3GPP TS 24.008: CONNECT message content(network to mobile station direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Connect 
message type 


IVIessage type 
10.4 


M 


V 


1 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


IE 


Progress indicator 


Progress indicator 
10.5.4.21 





TLV 


4 


4C 


Connected number 


Connected number 
10.5.4.13 





TLV 


3-14 


4D 


Connected subaddress 


Connected subaddress 
10.5.4.14 





TLV 


2-23 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 



9.3.5.1.1 Facility 

This information element may be used for functional operation of supplementary services. 

9.3.5.1 .2 Progress indicator 

This information element may be included by the network: 

in order to pass information about the call in progress e.g. in the event of interworking; and/or 
to make the MS attach the user connection for speech. 

9.3.5.1.3 User-user 

This information element may be included by the network if the remote user awarded the call included a user- user 
information element in the CONNECT message. 

9.3.5.2 Connect (mobile station to network direction) 

This message is sent by the called mobile station to the network to indicate call acceptance by the called user. 
See table 9.59a/3GPP TS 24.008. 
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Message type: CONNECT 

Significance: global 

Direction: mobile station to network 

Table 9.59a/3GPP TS 24.008: CONNECT message content (mobile station to network direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Connect 
message type 


IVIessage type 
10.4 


M 


V 


1 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


4D 


Connected subaddress 


Connected subaddress 
10.5.4.14 





TLV 


2-23 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 


7F 


SS version 


SS version indicator 
10.5.4.24 





TLV 


2-3 


2D 


Stream Identifier 


Stream Identifier 
10.5.4.28 





TLV 


3 



9.3.5.2.1 Facility 

This information element may be used for functional operation of supplementary services. 

9.3.5.2.2 User-user 

This information element is included when the answering mobile station wants to return user information to the calling 
remote user. 

9.3.5.2.3 SS version 

This information element shall not be included if the facility information element is not present in this message. 

This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 



9.3.5.2.4 



Stream Identifier 



This information element shall be included by a mobile station that supports multicall when a mobile station has 
indicated "No Bearer" as the SI value in the CALL CONFIRMED message. 



9.3.6 Connect acknowledge 



This message is sent by the network to the called mobile station to indicate that the mobile station has been awarded the 
call. It shall also be sent by the calling mobile station to the network to acknowledge the offered connection. 

See table 9.60/3GPP TS 24.008. 

Message type: CONNECT ACKNOWLEDGE 

Significance: local 

Direction: both 
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Table 9.60/3GPP TS 24.008: CONNECT ACKNOWLEDGE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Connect acknowledge 
message type 


Message type 
10.4 


M 


V 


1 



9.3.7 Disconnect 

9.3.7.1 Disconnect (network to mobile station direction) 

This message is sent by the network to indicate that the end-to-end connection is cleared. 
See table 9.61/3GPP TS 24.008. 

Message type: DISCONNECT 

Significance: global 

Direction: network to mobile station 

Table 9.61/3GPP TS 24.008: DISCONNECT message content (network to mobile station direction) 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Disconnect 
message type 


Message type 
10.4 


M 


V 


1 




Cause 


Cause 
10.5.4.11 


M 


LV 


3-31 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


1E 


Progress indicator 


Progress indicator 
10.5.4.21 





TLV 


4 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 


7B 


Allowed actions ${CCBS)$ 


Allowed actions 
10.5.4.27 





TLV 


3 



9.3.7.1.1 Facility 

This information element may be used for functional operation of supplementary services, such as the user-user service. 

9.3.7.1 .2 Progress indicator 

This information element is included by the network to make the MS attach the user connection for speech and react in 
a specific way during call clearing (see subclause 5.4.4). 



9.3.7.1.3 



User-user 



This information element may be included by the network when the remote user initiates call clearing and included a 
user-user information element in the DISCONNECT message. 

9.3.7.1 .4 Allowed actions $(CCBS)$ 

This information element may be included by the network to inform the MS about further possible reactions. 
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9.3.7.2 Disconnect (mobile station to network direction) 

This message is sent by the mobile station to request the network to clear an end-to-end connection. 
See table 9.61a/3GPP TS 24.008. 

Message type: DISCONNECT 

Significance: global 

Direction: mobile station to network 

Table 9.61a/3GPP TS 24.008: DISCONNECT message content (mobile station to network direction) 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Disconnect 
message type 


Message type 
10.4 


M 


V 


1 




Cause 


Cause 
10.5.4.11 


M 


LV 


3-31 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 


7F 


SB version 


88 version indicator 
10.5.4.24 





TLV 


2-3 



9.3.7.2.1 Facility 

This information element may be used for functional operation of supplementary services, such as the user-user service. 

9.3.7.2.2 User-user 

This information element is included when the mobile station initiates call clearing and wants to pass user information 
to the remote user at call clearing time. 

9.3.7.2.3 SS version 

This information element shall not be included if the/ac/Z/fy information element is not present in this message. 

This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 



9.3.8 Emergency setup 



This message is sent from the mobile station to initiate emergency call establishment. 
See table 9.62/3GPP TS 24.008. 

Message type: EMERGENCY SETUP 

Significance: global 

Direction: mobile station to network 
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Table 9.62/3GPP TS 24.008: EMERGENCY SETUP message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Emergency setup 
message type 


IVIessage type 
10.4 


M 


V 


1 


04 


Bearer capability 


Bearer capability 
10.5.4.5 





TLV 


3-11 


2D 


Stream Identifier 


Stream Identifier 
10.5.4.28 





TLV 


3 


40 


Supported Codecs 


Supported Codec List 
10.5.4.32 





TLV 


5-n 


2E 


Emergency category 


Service category 
10.5.4.33 





TLV 


3 



9.3.8.1 



Bearer capability 



If the element is not included, the network shall by default assume speech and select the speech codec according to 
subclauses 5.2.1.2 and 5.2.1.11. If this information element is included, it shall indicate speech, the appropriate speech 
version(s) and have the appropriate value of radio channel requirement field. 

This information element shall be included by an ME supporting CTM text telephony or supporting at least one speech 
version for GERAN other than GSM FR speech version 1. 

9.3.8.2 Stream Identifier 

This information element shall be included by the mobile station supporting multicall. 

9.3.8.3 Supported Codecs 

This information element shall be included if the mobile station supports UMTS radio access. 

9.3.8.4 Emergency category 

This information element shall be included if the emergency category is available from the SIM/USIM or the mobile 
station. 

If this information element is included, it shall indicate the selected emergency call category. 

If the element is not included, the network shall by default assume a non-specific emergency call. 



9.3.9 Facility 



9.3.9.1 



Facility (network to mobile station direction) 



This message is sent by the network to the mobile station to request or acknowledge a supplementary service. The 
supplementary service to be invoked and its associated parameters are specified in the facility information element. 

See table 9.62a/3GPP TS 24.008. 
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Message type: FACILITY 
Significance: local (NOTE 1) 
Direction: network to mobile station 

Table 9.62a/3GPP TS 24.008: FACILITY message content (network to mobile station direction) 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Facility 
message type 


Message type 
10.4 


M 


V 


1 




Facility (note 2) 


Facility 
10.5.4.15 


M 


LV 


1-? 



NOTE 1 : This message has local significance; however, it may carry information of global significance. 

NOTE 2: The facility information element has no upper length limit except that given by the maximum number of 
octets in a L3 message, see 3GPP TS 44.006 [19]. 



9.3.9.2 



Facility (mobile station to network direction) 



This message is sent by the mobile station to the network to request or acknowledge a supplementary service. The 
supplementary service to be invoked and its associated parameters are specified in the facility information element. 

See table 9.62b/3GPP TS 24.008. 

Message type: FACILITY 

Significance: local (note 1) 

Direction: mobile station to network 

Table 9.62b/3GPP TS 24.008: FACILITY message content (mobile station to network direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Facility 
message type 


Message type 
10.4 


M 


V 


1 




Facility (note 2) 


Facility 
10.5.4.15 


M 


LV 


1-? 


7F 


SB version 


SB version indicator 
10.5.4.24 





TLV 


2-3 



NOTE 1 : This message has local significance; however, it may carry information of global significance. 

NOTE 2: The facility information element has no upper length limit except that given by the maximum number of 
octets in a L3 message, see 3GPP TS 44.006 [19]. 



9.3.9.2.1 



SS version 



This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



328 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



9.3.10 Hold 

This message is sent by the mobile user to request the hold function for an existing call. 
See table 9.62c/3GPP TS 24.008 for the content of the HOLD message. 
For the use of this message, see 3GPP TS 24.010 [21]. 

Message type: HOLD 

Significance: local 

Direction: mobile station to network 

Table 9.62c/3GPP TS 24.008: HOLD message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Hold 
message type 


IVIessage type 
10.4 


M 


V 


1 



9.3.1 1 Hold Acknowledge 



This message is sent by the network to indicate that the hold function has been successfully performed. 
See table 9.62d/3GPP TS 24.008 for the content of the HOLD ACKNOWLEDGE message. 
For the use of this message, see 3GPP TS 24.010 [21]. 

Message type: HOLD ACKNOWLEDGE 

Significance: local 

Direction: network to mobile station 

Table 9.62d/3GPP TS 24.008: HOLD ACKNOWLEDGE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Hold Acknowledge 
message type 


Message type 
10.4 


M 


V 


1 



9.3.12 Hold Reject 



This message is sent by the network to indicate the denial of a request to hold a call. 
See table 9.62e/3GPP TS 24.008 for the content of the HOLD REJECT message. 
For the use of this message, see 3GPP TS 24.010 [21]. 

Message type: HOLD REJECT 

Significance: local 

Direction: network to mobile station 
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Table 9.62e/3GPP TS 24.008: HOLD REJECT message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Hold Reject 
message type 


Message type 
10.4 


M 


V 


1 




Cause 


10.5.4.11 


M 


LV 


3-31 



9.3.13 Modify 



This message is sent by the mobile station to the network or by the network to the mobile station to request a change in 
bearer capability for a call. 

See table 9.63/3GPP TS 24.008. 

Message type: MODIFY 

Significance: global 

Direction: both 

Table 9.63/3GPP TS 24.008: MODIFY message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




IVIodify 
message type 


Message type 
10.4 


M 


V 


1 




Bearer capability 


Bearer capability 
10.5.4.5 


M 


LV 


2-15 


7C 


Low layer comp. 


Low layer comp. 
10.5.4.18 





TLV 


2-18 


7D 


High layer comp. 


High layer comp. 
10.5.4.16 





TLV 


2-5 


A3 


Reverse call setup 
direction 


Reverse call setup 

direction 

10.5.4.22a 





T 


1 


A4 


Network-initiated Service 
Upgrade indicator 


Network-initiated Service 
Upgrade indicator 
10.5.4.3X 





T 


1 



9.3.1 3.1 Low layer compatibility 

This information element shall be included if it was included in the initial SETUP message. 

9.3.1 3.2 High layer compatibility 

This information element shall be included if it was included in the initial SETUP message. 

9.3.1 3.3 Reverse call setup direction 

This information element is included or omitted in the mobile to network direction according to the rules defined in 

subclause 5.3.4.3.1. 
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9.3.13.4 



Void 



9.3.13.5 Network-initiated Service Upgrade indicator 

This information element shall be included only if the MODIFY message was sent by the network to switch from 
speech to UDI/RDI multimedia due to a network-initiated service upgrade. 

9.3.14 Modify complete 

This message is sent by the mobile station to the network or by the network to the mobile station to indicate completion 
of a request to change bearer capability for a call. 

See table 9.64/3GPP TS 24.008. 

Message type: MODIFY COMPLETE 

Significance: global 

Direction: both 

Table 9.64/3GPP TS 24.008: MODIFY COMPLETE message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




IVIodify complete 
message type 


Message type 
10.4 


M 


V 


1 




Bearer capability 


Bearer capability 
10.5.4.5 


M 


LV 


2-15 


7C 


Low layer comp. 


Low layer comp. 
10.5.4.18 





TLV 


2-18 


7D 


High layer comp. 


High layer comp. 
10.5.4.16 





TLV 


2-5 


A3 


Reverse call setup 
direction 


Reverse call setup 

direction 

10.5.4.22a 





T 


1 



9.3.14.1 Low layer compatibility 

This information element shall be included if it was included in the initial SETUP message. 

9.3.14.2 High layer compatibility 

This information element shall be included if it was included in the initial SETUP message. 

9.3.1 4.3 Reverse call setup direction 

This information element is included or omitted according to the rules defined in subclause 5.3.4.3.2. 

9.3.15 Modify reject 

This message is sent by the mobile station to the network or by the network to the mobile station to indicate failure of a 
request to change the bearer capability for a call. 

See table 9.65/3GPP TS 24.008. 

Message type: MODIFY REJECT 

Significance: global 
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Direction: both 

Table 9.65/3GPP TS 24.008: MODIFY REJECT message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




IVIodify reject 
message type 


Message type 
10.4 


M 


V 


1 




Bearer capability 


Bearer capability 
10.5.4.5 


M 


LV 


2-15 




Cause 


Cause 
10.5.4.11 


M 


LV 


3-31 


7C 


Low layer comp. 


Low layer comp. 
10.5.4.18 





TLV 


2-18 


7D 


High layer comp. 


High layer comp. 
10.5.4.16 





TLV 


2-5 



9.3.1 5.1 Low layer compatibility 

This information element shall be included if it was included in the initial SETUP message. 

9.3.15.2 High layer compatibility 

This information element shall be included if it was included in the initial SETUP message. 

9.3.16 Notify 

This message is sent either from the mobile station or from the network to indicate information pertaining to a call, such 
as user suspended. 

See table 9.66/3GPP TS 24.008. 

Message type: NOTIFY 

Significance: access 

Direction: both 

Table 9.66/3GPP TS 24.008: NOTIFY message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Notify 
message type 


IVIessage type 
10.4 


M 


V 


1 




Notification indicator 


Notification indicator 
10.5.4.20 


M 


V 


1 



9.3.17 Progress 



This message is sent from the network to the mobile station to indicate the progress of a call in the event of 
interworking or in connection with the provision of in-band information/patterns. 
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See table 9.67/3GPP TS 24.008. 
Message type: PROGRESS 
Significance: global 
Direction: network to mobile station 



Table 9.67/3GPP TS 24.008: PROGRESS message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction Identifier 
10.3.2 


M 


V 


1/2 




Progress 
message type 


IVIessage type 
10.4 


M 


V 


1 




Progress indicator 


Progress indicator 
10.5.4.21 


M 


LV 


3 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 



9.3.17.1 



User-user 



This information element is included when the PROGRESS message is sent by the network when the call has been 
cleared by the remote user before it reached the active state to indicate that the remote user wants to pass user 
information at call clearing time. 

9.3.17.2 Progress indicator 

This information element may be included by the network: 

in order to pass information about the call in progress, e.g., in the event of interworking; 

to make the mobile station attach the user connection for speech; and/or 

to make a mobile station supporting multimedia CAT during the alerting phase of a mobile originated 
multimedia call establishment attach the user connection and setup an H.324 call. 

9.3.17a CC-Establishment $(CCBS)$ 

A mobile station that does not support the "Network initiated MO call" option shall treat this message as a message with 
message type not defined for the PD. 

This message is sent from the network to the mobile station to provide information on the call that the mobile station 
should attempt to establish. 

See Table 9.67a/3GPP TS 24.008. 

Message type: CC-ESTABLISHMENT 

Significance: local 

Direction: network to mobile station 
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Table 9.67a/3GPP TS 24.008: CC-Establishment message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




CC-Establishment 
message type 


Message type 
10.4 


M 


V 


1 




Setup container 


Container 
10.5.4.22b 


M 


LV 


3-n 



9.3.17a.1 



Void 



9.3.1 7a.2 Setup container 

This information element contains the contents of a SETUP message (Mobile Station to Network). 

9.3.17b CC-Establishment confirmed $(CCBS)$ 

A Network that does not support the "Network initiated MO call" option shall treat this message as a message with 
message type not defined for the PD. 

This message is sent by the mobile station to the network to indicate the requested channel characteristics for the call 
which may be initiated by the mobile station. 

See Table 9.67b/3GPP TS 24.008. 

Message type: CC-ESTABLISHMENT CONFIRMED 

Significance: local 

Direction: mobile station to network 

Table 9.67b/3GPP TS 24.008: CC-ESTABLISHMENT CONFIRMED message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




CC-Establishment 
confirmed 
message type 


Message type 
10.4 


M 


V 


1 


D- 


Repeat Indicator 


Repeat Indicator 
10.5.4.22 


C 


TV 


1 


04 


Bearer capability 1 


Bearer capability 
10.5.4.5 


M 


TLV 


3-16 


04 


Bearer capability 2 


Bearer capability 
10.5.4.5 





TLV 


3-16 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 


40 


Supported Codecs 


Supported Codec List 
10.5.4.32 





TLV 


5-n 



9.3.1 7b.1 Repeat indicator 

The repeat indicator information element shall be included if bearer capability 1 information element and bearer 
capability 2 IE are both included in the message. 
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9.3.1 7b. 2 Bearer capability 1 and bearer capability 2 

If, in any subsequent SETUP message to be sent on this transaction the bearer capability 1 information element is to be 
followed by the bearer capability 2 IE, then the bearer capability 2 IE shall be included in this message. 

9.3.1 7b.3 Cause 

This information element is included if the mobile station is compatible but the user is busy. 

9.3.1 7b.4 Supported Codecs 

This information element shall be included for speech calls, if the mobile station supports UMTS radio access. 

9.3.18 Release 

9.3.1 8.1 Release (network to mobile station direction) 

This message is sent, from the network to the mobile station to indicate that the network intends to release the 
transaction identifier, and that the receiving equipment shall release the transaction identifier after sending RELEASE 
COMPLETE. 

See table 9.68/3GPP TS 24.008. 

Message type: RELEASE 

Significance: local (note) 

Direction: network to mobile station 

Table 9.68/3GPP TS 24.008: RELEASE message content (network to mobile station direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Release 
message type 


IVIessage type 
10.4 


M 


V 


1 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 


08 


Second cause 


Cause 
10.5.4.11 





TLV 


4-32 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 



NOTE: This message has local significance; however, it may carry information of global significance when used 
as the first call clearing message. 

9.3.18.1.1 Cause 

This information element shall be included if this message is used to initiate call clearing. 



9.3.18.1.2 



Second cause 



This information element may be included under the conditions described in subclause 5.4.4. L2. 3 "Abnormal cases" 
(Clearing initiated by the network). 
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9.3.18.1.3 Facility 

This information element may be included for functional operation of supplementary services. 

9.3.18.1.4 User-user 

This information element may be included in the network to mobile station direction, when the RELEASE message is 
used to initiate call clearing, in order to transport user-user information from the remote user. 

9.3.1 8.2 Release (mobile station to network direction) 

This message is sent from the mobile station to the network to indicate that the mobile station intends to release the 
transaction identifier, and that the receiving equipment shall release the transaction identifier after sending RELEASE 
COMPLETE. 

See table 9.68a/3GPP TS 24.008. 

Message type: RELEASE 

Significance: local (note) 

Direction: mobile station to network direction 

Table 9.68a/3GPP TS 24.008: RELEASE message content (mobile station to network direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Release 
message type 


IVIessage type 
10.4 


M 


V 


1 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 


08 


Second cause 


Cause 
10.5.4.11 





TLV 


4-32 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 


7F 


SS version 


88 version indicator 
10.5.4.24 





TLV 


2-3 



NOTE: This message has local significance; however, it may carry information of global significance when used 
as the first call clearing message. 

9.3.18.2.1 Cause 

This information element shall be included if this message is used to initiate call clearing. 



9.3.18.2.2 



Second cause 



This information element may be included under the conditions described in subclause 5.4.3.5 "Abnormal cases" 
(Clearing initiated by the mobile station). 

9.3.18.2.3 Facility 

This information element may be included for functional operation of supplementary services. 
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9.3.18.2.4 



User-user 



This information element is included when the RELEASE message is used to initiate call clearing and the mobile 
station wants to pass user information to the remote user at call clearing time. 

9.3.18.2.5 SS version 

This information element shall not be included if the facility information element is not present in this message. 

This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 



9.3.18a Recall $(CCBS)$ 



A mobile station that does not support the "Network initiated MO call" option shall treat this message as a message with 
message type not defined for the PD. 

This message is sent from the network to the mobile station to initiate the sending of the SETUP message. In addition it 
provides information for user notification. 

See Table 9.68b/3GPP TS 24.008. 

Message type: RECALL 

Significance: local 

Direction: network to mobile station 

Table 9.68b/3GPP TS 24.008: Recall message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Recall 
message type 


Message type 
10.4 


M 


V 


1 




Recall Type 


Recall Type 
10.5.4.21a 


M 


V 


1 




Facility 


Facility 
10.5.4.15 


M 


LV 


2-n 



9.3.1 8a. 1 Recall Type 

The purpose of the recall type information element is to describe the reason for the recall. 

9.3.1 8a.2 Facility 

The information element shall be included for functional operation of supplementary services. 

9.3.19 Release complete 

9.3.1 9.1 Release complete (network to mobile station direction) 

This message is sent from the network to the mobile station to indicate that the network has released the transaction 
identifier and that the mobile station shall release the transaction identifier. 

See table 9.69/3GPP TS 24.008. 

Message type: RELEASE COMPLETE 
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Significance: local (note) 

Direction: network to mobile station direction 



Table 9.69/3GPP TS 24.008: RELEASE COMPLETE message content (network to mobile station 

direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Release complete 
message type 


Message type 
10.4 


M 


V 


1 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 



NOTE: This message has local significance; however, it may carry information of global significance when used 
as the first call clearing message. 

9.3.19.1.1 Cause 

This information element shall be included if the message is used to initiate call clearing. 

9.3.19.1.2 Facility 

This information element may be included for functional operation of supplementary services. 



9.3.19.1.3 



User-user 



This information element is included in the network to mobile station direction, when the RELEASE COMPLETE 
message is used to initiate call clearing, in order to transport user-user information from the remote user. 

9.3.1 9.2 Release complete (mobile station to network direction) 

This message is sent from the mobile station to the network to indicate that the mobile station has released the 
transaction identifier and that the network shall release the transaction identifier. 

See table 9.69a/3GPP TS 24.008. 

Message type: RELEASE COMPLETE 

Significance: local (note) 

Direction: mobile station to network direction 
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Table 9.69a/3GPP TS 24.008: RELEASE COMPLETE message content (mobile station to network 

direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Release complete 
message type 


Message type 
10.4 


M 


V 


1 


08 


Cause 


Cause 
10.5.4.11 





TLV 


4-32 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-131 


7F 


SS version 


SS version indicator 
10.5.4.24 





TLV 


2-3 



NOTE: This message has local significance; however, it may carry information of global significance when used 
as the first call clearing message. 

9.3.19.2.1 Cause 

This information element shall be included if the message is used to initiate call clearing. 

9.3.19.2.2 Facility 

This information element may be included for functional operation of supplementary services. 



9.3.19.2.3 



User-user 



This information element is included in the mobile station to network direction when the RELEASE COMPLETE 
message is used to initiate call clearing and the mobile station wants to pass user information to the remote user at call 
clearing time. 

9.3.19.2.4 SS version. 

This information element shall not be included if the facility information element is not present in this message. 

This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 

9.3.20 Retrieve 

This message is sent by the mobile user to request the retrieval of a held call. 
See table 9.69b/3GPP TS 24.008 for the content of the RETRIEVE message. 
For the use of this message, see 3GPP TS 24.010 [21]. 
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Table 9.69b/3GPP TS 24.008: RETRIEVE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Retrieve 
message type 


Message type 
10.4 


M 


V 


1 



9.3.21 Retrieve Acknowledge 

This message is sent by the network to indicate that the retrieve function has been successfully performed. 
See table 9.69c/3GPP TS 24.008 for the content of the RETRIEVE ACKNOWLEDGE message. 
For the use of this message, see 3GPP TS 24.010 [21]. 

Message type: RETRIEVE ACKNOWLEDGE 

Significance: local 

Direction: network to mobile station 

Table 9.69c/3GPP TS 24.008: RETRIEVE ACKNOWLEDGE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Retrieve Acknowledge 
message type 


Message type 
10.4 


M 


V 


1 



9.3.22 Retrieve Reject 



This message is sent by the network to indicate the inability to perform the requested retrieve function. 
See table 9.69d/3GPP TS 24.008 for the content of the RETRIEVE REJECT message. 
For the use of this message, see 3GPP TS 24.010 [21]. 

Message type: RETRIEVE REJECT 

Significance: local 

Direction: network to mobile station 
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Table 9.69d/3GPP TS 24.008: RETRIEVE REJECT message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Retrieve Reject 
Message type 


IVIessage type 
10.4 


M 


V 


1 




Cause 


10.5.4.11 


M 


LV 


3-31 



9.3.23 Setup 



9.3.23.1 Setup (mobile terminated call establishment) 

This message is sent by the network to the mobile station to initiate a mobile terminated call establishment. 
See table 9.70/3GPP TS 24.008. 

Message type: SETUP 

Significance: global 

Direction: network to mobile station 
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Table 9.70/3GPP TS 24.008: SETUP message content (network to mobile station direction) 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Setup 
Message type 


Message type 
10.4 


M 


V 


1 


D- 


BC repeat indicator 


Repeat indicator 
10.5.4.22 


C 


TV 


1 


04 


Bearer capability 1 


Bearer capability 
10.5.4.5 





TLV 


3-16 


04 


Bearer capability 2 


Bearer capability 
10.5.4.5 





TLV 


3-16 


1C 


Facility 


Facility 
10.5.4.15 





TLV 


2-? 


IE 


Progress indicator 


Progress indicator 
10.5.4.21 





TLV 


4 


34 


Signal 


Signal 
10.5.4.23 





TV 


2 


5C 


Calling party BCD 
Number 


Calling party BCD num. 
10.5.4.9 





TLV 


3-14 


5D 


Calling party sub- 
Address 


Calling party subaddr. 
10.5.4.10 





TLV 


2-23 


5E 


Called party BCD 
Number 


Called party BCD num. 
10.5.4.7 





TLV 


3-19 


6D 


Called party sub- 
Address 


Called party subaddr. 
10.5.4.8 





TLV 


2-23 


74 


Redirecting party BCD number 


Redirecting party BCD num. 
10.5.4.21b 





TLV 


3-19 


75 


Redirecting party sub-address 


Redirecting party subaddress. 
10.5.4.21c 





TLV 


2-23 


D- 


LLC repeat indicator 


Repeat indicator 
10.5.4.22 





TV 


1 


7C 


Low layer 
Compatibility 1 


Low layer comp. 
10.5.4.18 





TLV 


2-18 


7C 


Low layer 
Compatibility II 


Low layer comp. 
10.5.4.18 


C 


TLV 


2-18 


D- 


HLC repeat indicator 


Repeat indicator 
10.5.4.22 





TV 


1 


7D 


High layer 
Compatibility i 


High layer comp. 
10.5.4.16 





TLV 


2-5 


7D 


High layer 
Compatibility ii 


High layer comp. 
10.5.4.16 


C 


TLV 


2-5 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-35 


8- 


Priority 


Priority Level 
10.5.1.11 





TV 


1 


19 


Alert 


Alerting Pattern 
10.5.4.26 





TLV 


3 


2F 


Network Call Control 
Capabilities 


Network Call Control cap. 
10.5.4.29 





TLV 


3 


3A 


Cause of No CLI 


Cause of No CLI 
10.5.4.30 





TLV 


3 


41 


Backup bearer capability 


Backup bearer capability 
10.5.4.4a 





TLV 


3-15 



9.3.23.1.1 



BC repeat indicator 



The BC repeat indicator information element is included if and only if bearer capability 1 information element and 
bearer capability 2 IE are both present in the message. 
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9.3.23.1 .2 Bearer capability 1 and bearer capability 2 

The bearer capability 1 information element may be omitted in the case where the mobile subscriber is allocated only 
one directory number for all services (ref.: 3GPP TS 29.007 [38]). The bearer capability 2 IE is missing at least if the 
bearer capability 1 IE is missing. 

If the MSC wishes to indicate capability for an altenative call mode, which can be entered through fallback, this is 
indicated by adding a bearer capability information element (bearer capability) 2 element (see subclause 5.3.6). 

9.3.23.1.3 Facility 

This information element may be included for functional operation of supplementary services. 

9.3.23.1.4 Progress indicator 

This information element is included by the network 

in order to pass information about the call in progress e.g. in the event of interworking and/or 
to make the MS attach the user connection for speech. 

9.3.23.1 .4a Called party BCD number 

For all bands except for PCS 1900, the maximum length of this IE sent by the network shall be 13 octets 

9.3.23.1 .5 Called party subaddress 

Included in the Network-to-mobile station direction if the calling user includes a called party subaddress information 
element in the SETUP message. 

9.3.23.1 .6 LLC repeat indicator 

The LLC repeat indicator information element is included if and only if both following conditions hold: 

The BC repeat indicator IE is contained in the message. 

The low layer compatibility I IE is contained in the message. 
If included, the LLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE. 

9.3.23.1 .7 Low layer compatibility I 

Included in the network-to-mobile station direction if the calling user specified a low layer compatibility. 

9.3.23.1 .8 Low layer compatibility II 

Included if and only if the LLC repeat indicator information element is contained in the message. 

9.3.23.1 .9 HLC repeat indicator 

The HLC repeat indicator information element is included if and only both following conditions hold: 

The BC repeat indicator IE is contained in the message. 

The high layer compatibility i IE is contained in the message. 
If included, the HLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE. 

9.3.23.1 .1 High layer compatibility i 

Included in the network-to-mobile station direction if the calling user specified a high layer compatibility. 
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9.3.23.1 .1 1 High layer compatibility ii 

Included if and only if the HLC repeat indicator information element is contained in the message. 

9.3.23.1.12 User-user 

May be included in the network to called mobile station direction when the calling remote user included a user-user 
information element in the SETUP message. 

9.3.23.1 .1 3 Redirecting party BCD number 

May be included in the network to called mobile station direction when the call has been redirected. 

9.3.23.1.14 Redirecting party subaddress 

May be included in the network to called mobile station direction when the calling remote user included a called party 
subaddress in the SETUP message and the call has been redirected 

9.3.23.1.15 Priority 

May be included by the network to indicate the priority of the incoming call if eMLPP is used. 

9.3.23.1 .1 6 Alert $(Network Indication of Alerting in the MS)$ 

May be included by the network to give some indication about alerting (category or level). If supported in the MS, this 
optional indication is to be used by the MS as specified in 3GPP TS 22.101 [8]. 

9.3.23. 1 . 1 7 Network Call Control Capabilities 

This information shall be included by the network to indicate its call control capabilities if the network supports 
multicall.and there are no other ongoing calls to the MS. 

9.3.23.1.18 Cause of No CLI 

This IE may be included by the network as defined by 3GPP TS 24.081 [25]. 

When both Calling Party BCD number IE and Cause of No CLI IE are included in SETUP message then the Cause of 
No CLI IE provides additional information on why the number digits are not present. 

9.3.23.1 .1 9 Backup bearer capability 

The backup bearer capability IE may be included by the network only if there are no bearer capability lEs contained in 
the message. 

NOTE: The MSC may use the backup bearer capability IE if it is not able to provide a complete bearer 
capability IE. 



9.3.23.2 Setup (mobile originating call establishment) 

This message is sent from the mobile station to the network to initiate a mobile originating call establishment. 
See table 9.70a/3GPP TS 24.008. 

Message type: SETUP 

Significance: global 

Direction: mobile station to network 
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Table 9.70a/3GPP TS 24.008: SETUP message content (mobile station to network direction) 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Setup 
message type 


IVIessage type 
10.4 


M 


V 


1 


D- 


BC repeat indicator 


Repeat indicator 
10.5.4.22 


C 


TV 


1 


04 


Bearer capability 1 


Bearer capability 
10.5.4.5 


M 


TLV 


3-16 


04 


Bearer capability 2 


Bearer capability 
10.5.4.5 





TLV 


3-16 


1C 


Facility(simple recall alignment) 


Facility 
10.5.4.15 





TLV 


2- 


5D 


Calling party sub- 
address 


Calling party subaddr. 
10.5.4.10 





TLV 


2-23 


5E 


Called party BCD 
number 


Called party BCD num. 
10.5.4.7 


M 


TLV 


3-43 


6D 


Called party sub- 
address 


Called party subaddr. 
10.5.4.8 





TLV 


2-23 


D- 


LLC repeat indicator 


Repeat indicator 
10.5.4.22 





TV 


1 


7C 


Low layer 
compatibility 1 


Low layer comp. 
10.5.4.18 





TLV 


2-18 


7C 


Low layer 
compatibility II 


Low layer comp. 
10.5.4.18 





TLV 


2-18 


D- 


HLC repeat indicator 


Repeat indicator 
10.5.4.22 





TV 


1 


7D 


High layer 
compatibility i 


High layer comp. 
10.5.4.16 





TLV 


2-5 


7D 


High layer 
compatibility ii 


High layer comp. 
10.5.4.16 





TLV 


2-5 


7E 


User-user 


User-user 
10.5.4.25 





TLV 


3-35 


7F 


SS version 


SS version indicator 
10.5.4.24 





TLV 


2-3 


A1 


CLIR suppression 


CLIR suppression 
10.5.4.11a 


c 


T 


1 


A2 


CLIR invocation 


CLIR invocation 
10.5.4.11b 


c 


T 


1 


15 


CC capabilities 


Call Control Capabilities 
10.5.4.5a 





TLV 


4 


ID 


Facility $(CCBS)$ 
(advanced recall alignment) 


Facility 
10.5.4.15 





TLV 


2-? 


IB 


Facility (recall alignment 
Not essential) $(CCBS)$ 


Facility 
10.5.4.15 





TLV 


2-? 


2D 


Stream Identifier 


Stream Identifier 
10.5.4.28 





TLV 


3 


40 


Supported Codecs 


Supported Codec List 
10.5.4.32 





TLV 


5-n 


A3 


Redial 


Redial 
10.5.4.34 





T 


1 



9.3.23.2.1 



BC repeat indicator 



The BC repeat indicator information element is included if and only if bearer capability 1 IE and bearer capability 2 IE 
are both present in the message. 
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9.3.23.2.2 Facility 

The information element may be included for functional operation of supplementary services. 
Three different codings of this IE exist, for further details see 3GPP TS 24.010 [21]. 

9.3.23.2.3 LLC repeat indicator 

The LLC repeat indicator information element is included if and only if both following conditions hold: 
- The BC repeat indicator IE is contained in the message. 
The low layer compatibility I IE is contained in the message. 
If included, the LLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE. 

9.3.23.2.4 Low layer compatibility I 

The information element is included in the MS-to-network direction when the calling MS wants to pass low layer 
compatibility information to the called user. 

9.3.23.2.5 Low layer compatibility II 

Included if and only if the LLC repeat indicator information element is contained in the message. 

9.3.23.2.6 HLC repeat indicator 

The HLC repeat indicator information element is included if and only if both following conditions hold: 

The BC repeat indicator IE is contained in the message. 

The high layer compatibility i IE is contained in the message. 
If included, the HLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE. 

9.3.23.2.7 High layer compatibility i 

The information element is included when the calling MS wants to pass high layer compatibility information to the 
called user. 

9.3.23.2.8 High layer compatibility ii 

Included if and only if the HLC repeat indicator information element is contained in the message. 

9.3.23.2.9 User-user 

The information element is included in the calling mobile station to network direction when the calling mobile station 
wants to pass user information to the called remote user. 

9.3.23.2.10 SS version 

This information element shall not be included if ih& facility information element is not present in this message. 

This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element 
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21]. 

9.3.23.2.11 CLIP suppression 

The information element may be included by the MS (see 3GPP TS 24.081 [25]). If this information element is included 
the CLIR invocation IE shall not be included. 
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9.3.23.2.12 



CLIP invocation 



The information element may be included by the MS (see 3GPP TS 24.081 [25]). If this information element is included 
the CLIR suppression IE shall not be included. 

9.3.23.2.13 CC Capabilities 

This information element may be included by the mobile station to indicate its call control capabilities. 

9.3.23.2.14 Stream Identifier 

This information element shall be included by the mobile station supporting multicall. 

9.3.23.2.1 5 Bearer capability 1 and bearer capability 2 

If the mobile station wishes to indicate capability for an altenative call mode, which can be entered throughfallback, this 
is indicated by adding a bearer capability information element (bearer capability) 2 element (see subclause 5.3.6). 

9.3.23.2.16 Supported Codecs 

This information element shall be included for speech calls, if the mobile station supports UMTS radio access. 



9.3.23.2.17 



Redial 



This information element shall be included if the mobile station is attempting to set up a call to switch from speech to 
multimedia or vice-versa. 

9.3.23a Start CC $(CCBS)$ 

A Network that does not support the "Network initiated MO call" option shall treat this message as a message with 
message type not defined for the PD. 

This message is sent by the mobile station to the network to open a Call Control transaction which the network has 
requested the mobile station to open. 

See Table 9.70b/3GPP TS 24.008. 

Message type: START CC 

Significance: local 

Direction: mobile station to network 

Table 9.70b/3GPP TS 24.008: START CC message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Start CC 
message type 


IVIessage type 
10.4 


M 


V 


1 


15 


CC Capabilities 


Call Control Capabilities 
10.5.4.5a 





TLV 


4 



9.3.23a.1 CC Capabilities 

This information element may be included by the mobile station to indicate its call control capabilities 
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9.3.24 Start DTMF 

This message is sent by the mobile station to the network and contains the digit the network should reconvert back into 
a DTMF tone which is then applied towards the remote user. 

See table 9.71/3GPP TS 24.008. 

Message type: START DTMF 

Significance: local 

Direction: mobile station to network 

Table 9.71/3GPP TS 24.008: START DTMF message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Start DTMF 
message type 


IVIessage type 
10.4 


M 


V 


1 


2C 


Keypad facility 


Keypad facility 
10.5.4.17 


M 


TV 


2 



9.3.25 Start DTMF Acknowledge 

This message is sent by the network to the mobile station to indicate the successful initiation of the action requested by 
the START DTMF message (conversion of the digit contained in this message into a DTMF tone). 

See table 9.72/3GPP TS 24.008. 

Message type: START DTMF ACKNOWLEDGE 

Significance: local 

Direction: network to mobile station 

Table 9.72/3GPP TS 24.008: START DTMF ACKNOWLEDGE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Start DTMF acknowledge 
message type 


Message type 
10.4 


M 


V 


1 


2C 


Keypad facility 


Keypad facility 
10.5.4.17 


M 


TV 


2 



9.3.25.1 Keypad facility 



This information element contains the digit corresponding to the DTMF tone that the network applies towards the 
remote user. 



9.3.26 Start DTMF reject 



This message is sent by the network to the mobile station, if the network can not accept the START DTMF message. 
See table 9.73/3GPP TS 24.008. 

Message type: START DTMF REJECT 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



348 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



Significance: local 

Direction: network to mobile station 



Table 9.73/3GPP TS 24.008: START DTMF REJECT message content 



IE! 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Start DTMF reject 
message type 


Message type 
10.4 


M 


V 


1 




Cause 


Cause 
10.5.4.11 


M 


LV 


3-31 



9.3.27 Status 

This message is sent by the mobile station or the network at any time during a call to report certain error conditions 
listed in clause 8. It shall also be sent in response to a STATUS ENQUIRY message. 

See table 9.74/3GPP TS 24.008. 

Message type: STATUS 

Significance: local 

Direction: both 

Table 9.74/3GPP TS 24.008: STATUS message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Status 
message type 


Message type 
10.4 


M 


V 


1 




Cause 


Cause 
10.5.4.11 


M 


LV 


3-31 




Call state 


Call state 
10.5.4.6 


M 


V 


1 


24 


Auxiliary states 


Auxiliary states 
10.5.4.4 





TLV 


3 



9.3.27.1 Auxiliary states 

The information element is included if and only if the call state is "active" or "mobile originating modify" and any 
auxiliary state is different from "idle". For the definition of the auxiliary states see 3GPP TS 24.083 [27] and 3GPP TS 
24.084 [28] 

9.3.28 Status enquiry 

This message is sent by the mobile station or the network at any time to solicit a STATUS message from the peer layer 
3 entity. Sending of STATUS message in response to a STATUS ENQUIRY message is mandatory. 

See table 9.75/3GPP TS 24.008. 

Message type: STATUS ENQUIRY 

Significance: local 
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Direction: both 

Table 9.75/3GPP TS 24.008: STATUS ENQUIRY message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Status enquiry 
message type 


IVIessage type 
10.4 


M 


V 


1 



9.3.29 Stop DTMF 



This message is sent by a mobile station to the network and is used to stop the DTMF tone sent towards the remote user. 
See table 9.76/3GPP TS 24.008. 

Message type: STOP DTMF 

Significance: local 

Direction: mobile station to network 

Table 9.76/3GPP TS 24.008: STOP DTMF message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Stop DTIVIF 
message type 


IVIessage type 
10.4 


M 


V 


1 



9.3.30 Stop DTMF acknowledge 

This message is sent by the network to the mobile station to indicate that the sending of the DTMF tone has been 
stopped. 

See table 9.77/3GPP TS 24.008. 

Message type: STOP DTMF ACKNOWLEDGE 

Significance: local 

Direction: network to mobile station 

Table 9.77/3GPP TS 24.008: STOP DTMF ACKNOWLEDGE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




Stop DTMF acknowledge 
message type 


Message type 
10.4 


M 


V 


1 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



350 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



9.3.31 User information 

This message is sent by the mobile station to the network to transfer information to the remote user. This message is 
also sent by the network to the mobile station to deliver information transferred from the remote user. This message is 
used if the user-to-user transfer is part of an allowed information transfer as defined in 3GPP TS 24.010 [21]. 

See table 9.78/3GPP TS 24.008. 

Message type: USER INFORMATION 

Significance: access 

Direction: both 

Table 9.78/3GPP TS 24.008: USER INFORMATION message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Call control 

protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2 




User Information 
message type 


IVIessage type 
10.4 


M 


V 


1 




User-user 


User-user 
10.5.4.25 


M 


LV 


2-130 


AO 


More data 


More data 
10.5.4.19 





T 


1 



9.3.31.1 



User-user 



Some networks may only support a maximum length of 35 octets. Procedures for interworking are not currently defined 
and are for further study. 

R98 and earlier versions of this protocol specified a minimum length of 3 octets for this information element (not 
counting the lEI). To avoid interworking problems with mobile stations supporting only R98 or earlier versions of the 
protocol, the network shall deliver the User information message to these mobile stations only if the length of the User- 
user IE is greater or equal to 3 octets (not counting the lEI). 



9.3.31.2 



More data 



The information element is included by the sending user to indicate that another USER INFORMATION message 
pertaining to the same message block will follow. 

9.4 GPRS Mobility Management Messages 
9.4.1 Attacin request 

This message is sent by the MS to the network in order to perform a GPRS or combined GPRS attach. See 
table 9.4.1/3GPP TS 24.008. 

Message type: ATTACH REQUEST 

Significance: dual 

Direction: MS to network 
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Table 9.4.1/3GPP TS 24.008: ATTACH REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Attacli request message identity 


Message type 
10.4 


M 


V 


1 




IVIS network capability 


MS network capability 
10.5.5.12 


M 


LV 


3-9 




Attach type 


Attach type 
10.5.5.2 


M 


V 


1/2 




GPRS ciphering key sequence 
number 


Ciphering key sequence number 
10.5.1.2 


M 


V 


1/2 




DRX parameter 


DRX parameter 
10.5.5.6 


M 


V 


2 




Mobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


6-9 




Old routing area identification 


Routing area identification 
10.5.5.15 


M 


V 


6 




IVIS Radio Access capability 


MS Radio Access capability 
10.5.5.12a 


M 


LV 


6-51 


19 


Old P-TMSI signature 


P-TMSI signature 
10.5.5.8 





TV 


4 


17 


Requested READY timer 
value 


GPRS Timer 
10.5.7.3 





TV 


2 


9- 


TIVISI status 


TMSI status 
10.5.5.4 





TV 


1 


33 


PS LCS Capability 


PS LCS Capability 
10.5.5.22 





TLV 


3 


11 


IVIobile station classmark 2 


Mobile station classmark 2 
10.5.1.6 





TLV 


5 


20 


Mobile station classmark 3 


Mobile station classmark 3 
10.5.1.7 





TLV 


2-34 


40 


Supported Codecs 


Supported Codec List 
10.5.4.32 





TLV 


5-n 


58 


UE network capability 


UE network capability 
10.5.5.26 





TLV 


4-15 


1A 


Additional mobile identity 


Mobile identity 
10.5.1.4 





TLV 


7 


IB 


Additional old routing area 
identification 


Routing area identification 2 
10.5.5.15a 





TLV 


8 


5D 


Voice domain preference and 
UE's usage setting 


Voice domain preference and UE's 

usage setting 

10.5.5.28 





TLV 


3 


D- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 


E- 


P-TMSI type 


P-TMSI type 
10.5.5.29 





TV 


1 


C- 


MS network feature support 


MS network feature support 
10.5.1.15 





TV 


1 


14 


Old location area identification 


Location Area Identification 2 
10.5.5.30 





TLV 


7 



9.4.1.1 



Old P-TMSI signature 



The MS shall include this IE, if the MS holds a valid P-TMSI, P-TMSI signature and RAI, or if the TIN indicates 
"GUTI" and the MS holds a valid GUTI, or if the TIN is deleted and the MS holds a valid GUTI, but no valid P-TMSI 
and RAI. If the MS is configured for "Attach WithlMSI" as specified in 3GPP TS 24.368 [135] or 
3GPP TS 31.102 [112] and is attaching in a new PLMN which is neither the registered PLMN nor in the list of 
equivalent PLMNs, the MS shall not include this IE. 
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9.4.1 .2 Requested READY timer value 

This IE may be included if the MS wants to indicate a preferred value for the READY timer. 

9.4.1.3 TMS I status 

This IE shall be included if the MS performs a combined GPRS attach and no valid TMSI is available. 

9.4.1.4 PS LCS Capability 

This IE shall be included if the MS supports at least one positioning method for the provision of location services (LCS) 
via the PS domain in Gb-mode. 

9.4.1 .5 UE network capability 

An MS supporting S 1 mode shall include this IE to indicate its capabilities to the network. 

9.4.1 .6 Mobile station classmark 2 

This IE shall be included if the MS supports SRVCC to GERAN or UTRAN. 

9.4.1 .7 Mobile station classmark 3 

This IE shall be included if the MS supports SRVCC to GERAN. 

9.4.1.8 Supported Codecs 

This IE shall be included if the MS supports SRVCC to GERAN or UTRAN to indicate its supported speech codecs for 
CS speech calls. 

9.4.1 .9 Additional mobile identity 

The MS shall include this IE, if the TIN indicates "GUTI" and the MS holds a valid GUTI, P-TMSI and RAI. If the MS 
is configured for "AttachWithlMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and is attaching in 
a new PLMN which is neither the registered PLMN nor in the list of equivalent PLMNs, the MS shall not include this 
IE. 

9.4.1 .10 Additional old routing area identification 

The MS shall include this IE, if the TIN indicates "GUTI" and the MS holds a vaUd GUTI, P-TMSI and RAI. 

9.4.1 .1 1 Voice domain preference and UE's usage setting 

This IE shall be included: 

if the MS supports CS fallback and SMS over SGs, or the MS is configured to support IMS voice, or both; and 
- if the MS is E-UTRAN capable. 

9.4.1.12 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.4.1.13 P-TMSI type 

The MS shall include this IE if the type of identity in the Mobile identity IE is set to "TMSI/P-TMSI/M-TMSI". 
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9.4.1 .14 MS network feature support 

This IE shall be included if the MS supports extended periodic timer T3312. 

9.4.1 .15 Old location area identification 

The MS shall include this IE during a combined attach procedure, if the MS holds a valid LAI and the MS supports 
EMM combined procedures. 

9.4.2 Attach accept 

This message is sent by the network to the MS to indicate that the corresponding attach request has been accepted. See 
table 9.4.2/3GPP TS 24.008. 

Message type: ATTACH ACCEPT 

Significance: dual 

Direction: network to MS 
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Table 9.4.2/3GPP TS 24.008: ATTACH ACCEPT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Attacli accept message identity 


Message type 
10.4 


M 


V 


1 




Attach result 


Attach result 
10.5.5.1 


M 


V 


1/2 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 




Periodic RA update timer 


GPRS Timer 
10.5.7.3 


M 


V 


1 




Radio priority for SMS 


Radio priority 
10.5.7.2 


M 


V 


1/2 




Radio priority for T0IVI8 


Radio priority 2 
10.5.7.5 


M 


V 


1/2 




Routing area identification 


Routing area identification 
10.5.5.15 


M 


V 


6 


19 


P-TIVISI signature 


P-TMSI signature 
10.5.5.8 





TV 


4 


17 


Negotiated READY timer 
value 


GPRS Timer 
10.5.7.3 





TV 


2 


18 


Allocated P-TMSI 


Mobile identity 
10.5.1.4 





TLV 


7 


23 


MS identity 


Mobile identity 
10.5.1.4 





TLV 


7-10 


25 


GMM cause 


GMM cause 
10.5.5.14 





TV 


2 


2A 


T3302 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


8C 


Cell Notification 


Cell Notification 
10.5.5.21 





T 


1 


4A 


Equivalent PLMNs 


PLMN List 
10.5.1.13 





TLV 


5-47 


B- 


Network feature support 


Network feature support 
10.5.5.23 





TV 


1 


34 


Emergency Number List 


Emergency Number List 
10.5.3.13 





TLV 


5-50 


A- 


Requested MS Information 


Requested MS Information 
10.5.5.25 





TV 


1 


37 


T3319value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


38 


T3323 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


39 


T3312 extended value 


GPRS Timer 3 

10.5.7.4a 


o 


TLV 


3 



9.4.2.1 P-TMSI signature 

This IE may be included to assign an identity to the MS's GMM context. 

9.4.2.2 Negotiated READY timer value 

This IE may be included to indicate a value for the READY timer. 

9.4.2.3 Allocated P-TIVISI 

This IE may be included to assign a P-TMSI to an MS in case of a GPRS or combined GPRS attach. 
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9.4.2.4 MS identity 

This IE may be included to assign or unassign a TMSI to an MS in case of a combined GPRS attach. 

9.4.2.5 GMM cause 

This IE shall be included when IMSI attach for non-GPRS services was not successful during a combined GPRS attach 
procedure. 

9.4.2.6 T3302 value 

This IE may be included to indicate a value for the T3302 timer. 

9.4.2.7 Cell Notification (A/Gb mode only) 

In A/Gb mode, this IE shall be included by the SGSN in order to indicate the ability to support the Cell Notification. 

9.4.2.8 Equivalent PLMNs 

The Equivalent PLMNs information element is included if the network wants to inform the mobile station of equivalent 
PLMNs. 

9.4.2.9 Network feature support 

This IE may be included to inform the MS of the support of certain features. If this IE is not included then the 
respective features are not supported. 

9.4.2.10 Emergency Number List 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicates a list of emergency numbers valid 
within the same MCC as in the cell on which this IE is received. 

9.4.2.11 Requested MS Information 

This IE may be sent by the network to request the MS to provide feature-related information. 

9.4.2.12 T3319value 

This IE may be included to indicate a value for timer T3319. 

9.4.2.13 T3323 value 

The network may include this IE to indicate a value for timer T3323. 
If the IE is not included, the MS shall use the default value. 

9.4.2.1 4 T331 2 extended value 

The network may include this IE to provide the MS with a longer periodic routing area update timer. 

9.4.3 Attach complete 

This message is sent by the MS to the network if at least one of the following conditions is fulfilled: 

a P-TMSI and/or a TMSI was included within the attach accept message; or 

the network has requested the MS to provide feature-related information. 
See table 9.4.3/3GPP TS 24.008. 
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Table 9.4.3/3GPP TS 24.008: ATTACH COMPLETE message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Attacli complete message identity 


IVIessage type 
10.4 


M 


V 


1 


27 


Inter RAT handover information 


Inter RAT information container 
10.5.5.24 





TLV 


3-250 


2B 


E-UTRAN inter RAT handover 
information 


E-UTRAN inter RAT information 
container 10.5.5.27 





TLV 


3-257 



9.4.3.1 Inter RAT handover information 

This IE shall be included if the network has requested this information in the attach accept message. 

9.4.3.2 E-UTRAN inter RAT handover information 

This IE shall be included if the network has requested this information in the attach accept message. 



9.4.4 Attach reject 



This message is sent by the network to the MS to indicate that the corresponding attach request has been rejected. See 
table 9.4.4/3GPP TS 24.008. 

Message type: ATTACH REJECT 

Significance: dual 

Direction: network to MS 

Table 9.4.4/3GPP TS 24.008: ATTACH REJECT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


v 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


v 


1/2 




Attach reject message identity 


Message type 
10.4 


M 


v 


1 




GMM cause 


GMM cause 
10.5.5.14 


M 


v 


1 


2A 


T3302 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


3A 


T3346 value 


GPRS timer 2 
10.5.7.4 





TLV 


3 



9.4.4.1 T3302 value 

This IE may be included to indicate a value for the T3302 timer. 
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In lu mode, if the MS is not attaching for emergency services, the network shall not include this IE if this message is to 
be sent non-integrity protected. If the MS is attaching for emergency bearer services, the network may include this IE if 
this message is to be sent non-integrity protected. 

In lu mode, if the MS is not attaching for emergency services, the MS shall ignore the contents of this IE if this message 
is received without integrity protection. If the MS is attaching for emergency bearer services, the MS shall use the 
received contents of this IE if this message is received without integrity protection. 

If this IE is not included or if in lu mode the message is not integrity protected, the MS shall use the default value. 

9.4.4.2 T3346 value 

This IE may be included when the NAS level mobility management congestion control is active. 



9.4.5 Detach request 



9.4.5.1 Detach request (mobile terminated detach) 

This message is sent by the network to request the release of a GMM context. See table 9.4.5. 1/3GPP TS 24.008. 
Message type: DETACH REQUEST 
Significance: dual 
Direction: network to MS 

Table 9.4.5.1/3GPP TS 24.008:DETACH REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Detach request message identity 


Message type 
10.4 


M 


V 


1 




Detach type 


Detach type 
10.5.5.5 


M 


V 


1/2 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 


25 


GIVIIVI cause 


GIVIM cause 
10.5.5.14 





TV 


2 



9.4.5.1.1 GMM cause 

This IE shall be included in case the detach reason has to be indicated to the MS, e.g. due to a failed IMEI check. 

9.4.5.2 Detach request (mobile originating detach) 

This message is sent by the MS to request the release of a GMM context. See table 9.4.5.2/3GPP TS 24.008. 
Message type: DETACH REQUEST 
Significance: dual 
Direction: MS to network 
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Table 9.4.5.2/3GPP TS 24.008:DETACH REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Sl<ip indicator 
10.3.1 


M 


V 


1/2 




Detacti request message identity 


Message type 
10.4 


M 


V 


1 




Detacti type 


Detacli type 
10.5.5.5 


M 


V 


1/2 




Spare lialf octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


18 


P-TMSI 


Mobile identity 
10.5.1.4 





TLV 


7 


19 


P-TIVISI signature 


P-TMSI signature 2 
10.5.5.8a 





TLV 


5 



9.4.5.2.1 P-TMSI 

This IE shall be included by the MS, if the P-TMSI is available. 

9.4.5.2.2 P-TMSI signature 

This IE shall be included if the MS has a valid P-TMSI signature. 



9.4.6 Detach accept 



9.4.6.1 



Detach accept (mobile terminated detach) 



This message is sent by the MS to indicate that the detach procedure has been completed. See table 9.4.6. 1/3GPP TS 

24.008. 

Message type: DETACH ACCEPT 
Significance: dual 
Direction: MS to network 

Table 9.4.6.1/3GPP TS 24.008:DETACH ACCEPT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Detacli accept message identity 


Message type 
10.4 


M 


V 


1 



9.4.6.2 



Detach accept (mobile originating detach) 



This message is sent by the network to indicate that the detach procedure has been completed. See table 9.4.6. 2/3GPP 
TS 24.008. 

Message type: DETACH ACCEPT 

Significance: dual 

Direction: network to MS 
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Table 9.4.6.2/3GPP TS 24.008:DETACH ACCEPT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Detach accept message identity 


Message type 
10.4 


M 


V 


1 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 



9.4.7 P-TMSI reallocation command 

This message is sent by the network to the MS to reallocate a P-TMSI. See table 9.4.7/3GPP TS 24.008. 
Message type: P-TMSI REALLOCATION COMMAND 
Significance: dual 
Direction: network to MS 

Table 9.4.7/3GPP TS 24.008: P-TMSI REALLOCATION COMMAND message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




P-TMSI reallocation command 
message identity 


Message type 
10.4 


M 


V 


1 




Allocated P-TMSI 


Mobile identity 
10.5.1.4 


M 


LV 


6 




Routing area identification 


Routing area identification 
10.5.5.15 


M 


V 


6 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


19 


P-TMSI signature 


P-TMSI signature 
10.5.5.8 





TV 


4 



9.4.7.1 P-TMSI signature 

This IE may be included to assign an identity to the MS's GMM context. 

9.4.8 P-TMSI reallocation complete 

This message is sent by the MS to the network to indicate that reallocation of a P-TMSI has taken place. See 
table 9.4.8/3GPP TS 24.008. 

Message type: P-TMSI REALLOCATION COMPLETE 

Significance: dual 

Direction: MS to network 
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Table 9.4.8/3GPP TS 24.008: P-TMS! REALLOCATION COMPLETE message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




P-TIVISI reallocation complete 
message identity 


IVIessage type 
10.4 


M 


V 


1 



9.4.9 Authentication and cipinering request 

This message is sent by the network to the MS to initiate authentication of the MS identity. Additionally, the ciphering 
mode is set, indicating whether ciphering will be performed or not. See table 9.4.9/3GPP TS 24.008. 

Message type: AUTHENTICATION AND CIPHERING REQUEST 

Significance: dual 

Direction: network to MS 

Table 9.4.9/TS 24.008: AUTHENTICATION AND CIPHERING REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Authentication and ciphering 
request message identity 


Message type 
10.4 


M 


V 


1 




Ciphering algorithm 


Ciphering algorithm 
10.5.5.3 


M 


V 


1/2 




IMEISV request 


IMEISV request 
10.5.5.10 


M 


V 


1/2 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 




A&C reference number 


A&C reference number 
10.5.5.19 


M 


V 


1/2 


21 


Authentication parameter RAND 


Authentication parameter RAND 
10.5.3.1 





TV 


17 


8- 


GPRS ciphering key sequence 
number 


Ciphering key sequence number 
10.5.1.2 


C 


TV 


1 


28 


Authentication parameter 
AUTN 


Authentication parameter AUTN 
10.5.3.1.1 





TLV 


18 



9.4.9.1 Authentication Parameter RAND 

This IE shall only be included if authentication shall be performed. 

9.4.9.2 GPRS ciphering key sequence number 

This IE is included if and only if the Authentication parameter RAND is contained in the message. 



9.4.9.3 



Authentication Parameter AUTN 



This IE shall be present if and only if the authentication challenge is a UMTS authentication challenge. The presence or 
absence of this IE defines- in the case of its absence- a GSM authentication challenge or- in the case of its presence- a 
UMTS authentication challenge. 

The MS shall ignore the IE if a SIM is inserted in the MS. 
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In UMTS, the MS shall reject the AUTHENTICATION & CIPHERING REQUEST message as specified in 
subclause 4.7.7.5.1 if this IE is not present and a USIM is inserted in the MS. 

9.4.10 Authentication and cipinering response 

This message is sent by the MS to the network in response to an Authentication and ciphering request message. See 
table 9.4.10/3GPP TS 24.008. 

Message type: AUTHENTICATION AND CIPHERING RESPONSE 

Significance: dual 

Direction: MS to network 

Table 9.4.1 0/3GPP TS 24.008: AUTHENTICATION AND CIPHERING RESPONSE message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Authentication and ciphering 
response message identity 


GPRS message type 
10.4 


M 


V 


1 




A&C reference number 


A&C reference number 
10.5.5.19 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


22 


Authentication parameter 
Response 


Authentication Response parameter 
10.5.3.2 





TV 


5 


23 


IMEISV 


Mobile identity 
10.5.1.4 





TLV 


11 


29 


Authentication Response 
parameter (extension) 


Authentication Response parameter 
10.5.3.2.1 





TLV 


3-14 



9.4.10.1 Authentication Response Parameter 

This IE is included if authentication was requested within the corresponding authentication and ciphering request 
message. This IE contains the SRES, if the authentication challenge was for GSM or the RES (all or just the 4 most 
significant octets of) if it is a UMTS authentication challenge (see also subclause 9.4.10.2) 

9.4.10.2 IMEISV 

This IE is included if requested within the corresponding authentication and ciphering request message. 

9.4.10.3 Authentication Response Parameter (extension) 

This IE shall be included if and only if the authentication challenge was a UMTS authentication challenge and the RES 
parameter is greater than 4 octets in length. It shall contain the least significant remaining bits of the RES (the four most 
significant octets shall be sent in the Authentication Response Parameter IE (see subclause 9.2.3.1)) 

This IE shall not be included if a SIM is inserted in the MS. 

9.4.10a Authentication and Cipinering Failure 

This message is sent by the mobile station to the network to indicate that authentication of the network has failed. See 
table 9.4.10a/3GPP TS 24.008. 

Message type: AUTHENTICATION AND CIPHERING FAILURE 

Significance: dual 

Direction: mobile station to network 
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Table 9.4.1 0a/3GPP TS 24.008: AUTHENTICATION AND CIPHERING FAILURE message content 



lEI 


Information element 


Type/Reference 


Presence 


Format 


Length 




Mobility management 
Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip Indicator 


Skip Indicator 
10.3.1 


M 


V 


1/2 




Authentication and Ciphering 

Failure 

IVIessage type 


Message type 
10.4 


M 


V 


1 




GMM Cause 


GMM Cause 
10.5.5.14 


M 


V 


1 


30 


Authentication Failure parameter 


Authentication Failure parameter 
10.5.3.2.2 





TLV 


16 



9.4.1 Oa.1 Authentication Failure parameter 

This IE shall be sent if and only if the GMM cause was "Synch failure". It shall include the response to the 
authentication challenge from the USIM, which is made up of the AUTS parameter (see 3GPP TS 33.102 [5a]). 

9.4.1 1 Authentication and ciphering reject 

This message is sent by the network to the MS to indicate that authentication has failed (and that the receiving MS shall 
abort all activities). See table 9.4.11/3GPP TS 24.008. 

Message type: AUTHENTICATION AND CIPHERING REJECT 

Significance: dual 
Direction: network to MS 

Table 9.4.1 1/3GPP TS 24.008: AUTHENTICATION AND CIPHERING REJECT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Authentication and ciphering 
reject message identity 


Message type 
10.4 


M 


V 


1 



9.4.12 Identity request 



This message is sent by the network to the MS to request submission of the MS identity according to the specified 
identity type. See table 9.4.12/3GPP TS 24.008. 

Message type: IDENTITY REQUEST 

Significance: dual 

Direction: network to MS 
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Table 9.4.1 2/3GPP TS 24.008: IDENTITY REQUEST message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Sl<ip indicator 
10.3.1 


M 


V 


1/2 




Identity request message identity 


IVIessage type 
10.4 


M 


V 


1 




Identity type 


Identity type 2 
10.5.5.9 


M 


V 


1/2 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 



9.4.13 Identity response 



This message is sent by the MS to the network in response to an identity request message providing the requested 
identity. See table 9.4.13/3GPP TS 24.008. 

Message type: IDENTITY RESPONSE 

Significance: dual 

Direction: MS to network 

Table 9.4.1 3/3GPP TS 24.008: IDENTITY RESPONSE message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Identity response message 
identity 


IVIessage type 
10.4 


M 


V 


1 




IVIobile identity 


Mobile identity 
10.5.1.4 


M 


LV 


4-10 



9.4.14 Routing area update request 



This message is sent by the MS to the network either to request an update of its location file or to request an IMSI 
attach for non-GPRS services. See table 9.4.14/3GPP TS 24.008. 

Message type: ROUTING AREA UPDATE REQUEST 

Significance: dual 

Direction: MS to network 
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Table 9.4.1 4/3GPP TS 24.008: ROUTING AREA UPDATE REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Routing area update request 
message identity 


Message type 
10.4 


M 


V 


1 




Update type 


Update type 
10.5.5.18 


M 


V 


1/2 




GPRS ciphering l<ey sequence 
number 


Ciphering key sequence number 
10.5.1.2 


M 


V 


1/2 




Old routing area identification 


Routing area identification 
10.5.5.15 


M 


V 


6 




IVIS Radio Access capability 


MS Radio Access capability 
10.5.5.12a 


M 


LV 


6-51 


19 


Old P-TMSI signature 


P-TMSI signature 
10.5.5.8 





TV 


4 


17 


Requested READY timer value 


GPRS Timer 
10.5.7.3 





TV 


2 


27 


DRX parameter 


DRX parameter 
10.5.5.6 





TV 


3 


9- 


TMSI status 


TMSI status 
10.5.5.4 





TV 


1 


18 


P-TMSI 


Mobile identity 
10.5.1.4 





TLV 


7 


31 


MS network capability 


MS network capability 
10.5.5.12 





TLV 


4-10 


32 


PDP context status 


PDP context status 
10.5.7.1 





TLV 


4 


33 


PS LCS Capability 


PS LCS Capability 
10.5.5.22 





TLV 


3 


35 


MBMS context status 


MBMS context status 
10.5.7.6 





TLV 


2-18 


58 


UE network capability 


UE network capability 
10.5.5.26 





TLV 


4-15 


1A 


Additional mobile identity 


Mobile identity 
10.5.1.4 





TLV 


7 


IB 


Additional old routing area 
identification 


Routing area identification 2 
10.5.5.15a 





TLV 


8 


11 


Mobile station classmark 2 


Mobile station classmark 2 
10.5.1.6 





TLV 


5 


20 


Mobile station classmark 3 


Mobile station classmark 3 
10.5.1.7 





TLV 


2-34 


40 


Supported Codecs 


Supported Codec List 
10.5.4.32 





TLV 


5-n 


5D 


Voice domain preference and 
UE's usage setting 


Voice domain preference and UE's 

usage setting 

10.5.5.28 





TLV 


3 


E- 


P-TMSI type 


P-TMSI type 
10.5.5.29 





TV 


1 


D- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 


C- 


MS network feature support 


MS network feature support 
10.5.1.15 





TV 


1 


14 


Old location area identification 


Location Area Identification 2 
10.5.5.30 





TLV 


7 



9.4.14.1 Old P-TMSI signature 

The MS shall include this IE, if the MS received the IE from the network in an ATTACH ACCEPT or ROUTING 
AREA UPDATE ACCEPT message, or if the TIN indicates "GUTI" and the MS holds a valid GUTI. 
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9.4.1 4.2 Requested READY timer value 

This IE may be included if the MS wants to indicate a preferred value for the READY timer. 

9.4.14.3 DRX parameter 

This IE shall be included if the MS changes the access network from GSM to UMTS, or the MS wants to indicate new 
DRX parameters to the network. 

9.4.14.4 TMS I status 

This IE shall be included if the MS performs a combined routing area update and no valid TMSI is available. 

9.4.14.5 P-TMSI (lu mode only) 

This IE shall be included by the MS. 

9.4.1 4.6 MS network capability 

This IE shall be included by the MS to indicate its capabilities to the network. 

9.4.1 4.7 PDP context status 

This IE shall be included by the MS. 

9.4.14.8 PS LCS Capability 

This IE shall be included if the MS supports at least one positioning method for the provision of location services (LCS) 
via the PS domain in Gb-mode. 

9.4.1 4.9 MBMS context status 

This IE shall be included by the MS, if it has MBMS contexts with an SM state different from PDP-INACTIVE. 

9.4.14.10 Additional mobile identity 

This IE shall be included by the MS, if the TIN indicates "GUTI" and the MS holds a valid GUTI and P-TMSI and RAI. 

9.4.14.1 1 Additional old routing area identification 

This IE shall be included by the MS, if the TIN indicates "GUTI" and the MS holds a valid GUTI and P-TMSI and RAI. 

9.4.1 4.1 2 UE network capability 

An MS supporting SI mode shall include this IE, unless the update type indicates "periodic update". 

9.4.1 4.1 3 Mobile station classmark 2 

This IE shall be included if the MS supports SRVCC to GERAN or UTRAN. 

9.4.1 4.1 4 Mobile station classmark 3 

This IE shall be included if the MS supports SRVCC to GERAN. 

9.4.14.15 Supported Codecs 

This IE shall be included if the MS supports SRVCC to GERAN or UTRAN to indicate its supported speech codecs for 
CS speech calls. 
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9.4.1 4.1 6 Voice domain preference and UE's usage setting 

This IE shall be included: 

if the MS supports CS fallback and SMS over SGs, or the MS is configured to support IMS voice, or both, and 
- if the MS is E-UTRAN capable. 

9.4.14.17 P-TMSItype 

The MS shall include this IE. 

9.4.14.18 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.4.1 4.1 9 MS network feature support 

This IE shall be included if the MS supports extended periodic timer T3312. 

9.4.14.20 Old location area identification 

The MS shall include this IE during a combined routing area updating procedure, if the MS holds a valid LAI and the 
MS supports EMM combined procedures. 

9.4.15 Routing area update accept 

This message is sent by the network to the MS to provide the MS with GPRS mobility management related data in 
response to a routing area update request message. See table 9.4.15/3GPP TS 24.008. 

Message type: ROUTING AREA UPDATE ACCEPT 

Significance: dual 

Direction: network to MS 
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Table 9.4.1 5/3GPP TS 24.008: ROUTING AREA UPDATE ACCEPT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Routing area update accept 
message identity 


Message type 
10.4 


M 


V 


1 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 




Update result 


Update result 
10.5.5.17 


M 


V 


1/2 




Periodic RA update timer 


GPRS Timer 
10.5.7.3 


M 


V 


1 




Routing area identification 


Routing area identification 
10.5.5.15 


M 


V 


6 


19 


P-TMSI signature 


P-TMSI signature 
10.5.5.8 





TV 


4 


18 


Allocated P-TMSI 


Mobile identity 
10.5.1.4 





TLV 


7 


23 


MS identity 


Mobile identity 
10.5.1.4 





TLV 


7-10 


26 


List of Receive N-PDU Numbers 


Receive N-PDU Number list 
10.5.5.11 





TLV 


4- 19 


17 


Negotiated READY timer value 


GPRS Timer 
10.5.7.3 





TV 


2 


25 


GIVIM cause 


GMM cause 
10.5.5.14 





TV 


2 


2A 


T3302 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


8C 


Cell Notification 


Cell Notification 
10.5.5.21 





T 


1 


4A 


Equivalent PLI\/INs 


PLMN List 
10.5.1.13 





TLV 


5-47 


32 


PDP context status 


PDP context status 
10.5.7.1 





TLV 


4 


B- 


Networl< feature support 


Network feature support 
10.5.5.23 





TV 


1 


34 


Emergency Number List 


Emergency Number List 
10.5.3.13 





TLV 


5-50 


35 


IVIBMS context status 


MBMS context status 
10.5.7.6 





TLV 


2-18 


A- 


Requested MS information 


Requested MS Information 
10.5.5.25 





TV 


1 


37 


T3319 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


38 


T3323 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


39 


T3312 extended value 


GPRS timer 3 
10.5.7.4a 





TLV 


3 



9.4.15.1 P-TMSI signature 

This IE may be included to assign an identity to the MS's GMM context. 

9.4.15.2 Allocated P-TMSI 

This IE may be included to assign a P-TMSI to an MS in case of a GPRS or combined routing area updating procedure. 



9.4.15.3 



MS identity 



This IE may be included to assign or unassign a TMSI to a MS in case of a combined routing area updating procedure. 
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9.4.1 5.4 List of Receive N-PDU Numbers 

This IE shall be included in case of an inter SGSN routing area updating from A/Gb mode to A/Gb mode, or inter 
SGSN routing area updating from lu mode to A/Gb mode, or intra SGSN routing area updating from lu mode to A/Gb 
mode, if there are PDP contexts that have been activated in LLC acknowledged transfer mode. 

9.4.1 5.5 Negotiated READY timer value 

This IE may be included to indicate a value for the READY timer. 

9.4.15.6 G MM cause 

This IE shall be included if the combined GPRS routing area updating procedure was successful for GPRS services 
only. 

9.4.15.7 T3302 value 

This IE may be included to indicate a value for the T3302 timer. 

In lu mode, if the MS is not attached for emergency bearer services, the network shall not include this IE if this message 
is to be sent non-integrity protected. If the MS is attached for emergency bearer services, the network may include this 
IE if this message is to be sent non-integrity protected. 

In lu mode, if this message is received without integrity protection the MS not attached for emergency bearer services 
shall ignore the contents of this IE and use the last received value if available. If there is no last received value, the MS 
shall use the default value. If the MS is attached for emergency bearer services, the MS shall use the received contents 
of this IE if this message is received without integrity protection. 

If this IE is not included in the message in A/Gb mode or if in lu mode this IE is not included in an integrity protected 
message, the MS shall use the default value. 

9.4.1 5.8 Cell Notification (A/Gb mode only) 

In A/Gb mode, this IE shall be included if by the SGSN in order to indicate the ability to support the Cell Notification. 

9.4.15.9 Equivalent PLMNs 

The Equivalent PLMNs information element is included if the network wants to inform the mobile station of equivalent 
PLMNs. 

9.4.1 5.1 PDP context status 

This IE shall be included by the NW. 

9.4.15.1 1 Network feature support 

This IE may be included to inform the MS of the support of certain features. If this IE is not included then the 
respective features are not supported. 

9.4.1 5.1 2 Emergency Number List 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicates a list of emergency numbers valid 
within the same MCC as in the cell on which this IE is received. 

9.4.1 5.1 3 MBMS context status 

This IE shall be included by the network, if it has MBMS contexts for the MS with an SM state different from PDP- 
INACTIVE. 
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9.4.15.14 Requested MS Information 

This IE may be sent by the network to request the MS to provide feature-related information. 

9.4.15.15 T3319value 

This IE may be included to indicate a value for timer T3319. 

9.4.15.16 T3323 value 

The network may include this IE to indicate a value for timer T3323. 
If the IE is not included, the MS shall use the default value. 

9.4.1 5.1 7 T331 2 extended value 

The network may include this IE to provide the MS with a longer periodic routing area update timer. 

9.4.1 6 Routing area update complete 

This message shall be sent by the MS to the network in response to a routing area update accept message if at least one 
of the following conditions is fulfilled: 

a P-TMSI and/or a TMSI has been assigned; 

there are established LLC connections; or 

the network has requested the MS to provide feature-related information. 

See table 9.4.16/3GPP TS 24.008. 

Message type: ROUTING AREA UPDATE COMPLETE 

Significance: dual 

Direction: MS to network 

Table 9.4.1 6/3GPP TS 24.008: ROUTING AREA UPDATE COMPLETE message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Routing area update complete 
message identity 


Message type 
10.4 


M 


V 


1 


26 


List of Receive N-PDU Numbers 


Receive N-PDU Number list 
10.5.5.11 





TLV 


4-19 


27 


Inter RAT handover information 


Inter RAT information container 
10.5.5.24 





TLV 


3-250 


2B 


E-UTRAN inter RAT handover 
information 


E-UTRAN inter RAT information 
container 10.5.5.27 





TLV 


3-257 



9.4.1 6.1 List of Receive N-PDU Numbers 

This IE shall be included if the routing area update accept message contained this IE. 

9.4.1 6.2 Inter RAT handover information 

This IE shall be included if the network has requested this information in the routing area update accept message. 
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9.4.1 6.3 E-UTRAN inter RAT handover information 

This IE shall be included if the network has requested this information in the routing area update accept message. 



9.4.17 Routing area update reject 



This message is sent by the network to the MS in order to reject the routing area update procedure. See 
table 9.4.17/3GPP TS 24.008. 

Message type: ROUTING AREA UPDATE REJECT 

Significance: dual 

Direction: network to MS 

Table 9.4.1 7/3GPP TS 24.008: ROUTING AREA UPDATE REJECT message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Routing area update reject 
message identity 


IVIessage type 
10.4 


M 


V 


1 




GMM cause 


GMM cause 
10.5.5.14 


M 


V 


1 




Force to standby 


Force to standby 
10.5.5.7 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


2A 


T3302 value 


GPRS Timer 2 
10.5.7.4 





TLV 


3 


3A 


T3346 value 


GPRS timer 2 
10.5.7.4 





TLV 


3 



9.4.17.1 



T3302 value 



This IE may be included to indicate a value for the T3302 timer. 

In lu mode, if the MS is not attached for emergency bearer services, the network shall not include this IE if this message 
is to be sent non-integrity protected. If the MS is attached for emergency bearer services, the network may include this 
IE if this message is to be sent non-integrity protected. 

In lu mode, the MS not attached for emergency bearer services shall ignore the contents of this IE if this message is 
received without integrity protection. If the MS is attached for emergency bearer services, the MS shall use the received 
contents of this IE if this message is received without integrity protection. 

If this IE is not included or if in lu mode the message is not integrity protected, the MS shall use the default value. 

9.4.17.2 T3346 value 

This IE may be included when the general NAS level mobility management congestion control is active. 

9.4.18 GMM Status 

This message is sent by the MS or by the network at any time to report certain error conditions listed in clause 8. See 
table 9.4.18/3GPP TS 24.008. 

Message type: GMM STATUS 

Significance: local 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



371 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



Direction: both 

Table 9.4.1 8/3GPP TS 24.008: GMM STATUS message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




GMM Status message identity 


Message type 
10.4 


M 


V 


1 




GMM cause 


GMM cause 
10.5.5.14 


M 


V 


1 



9.4.19 GMM Information 

This message is sent by the network at any time to sent certain information to the MS. 
See table 9.4.19/3GPP TS 24.008. 

Message type: GMM INFORMATION 

Significance: local 

Direction: network to MS 

Table 9.4.1 9/3GPP TS 24.008: GMM INFORMATION message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Skip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




GMM Information message 
identity 


Message type 
10.4 


M 


V 


1 


43 


Full name for network 


Network name 
10.5.3.5a 





TLV 


3-? 


45 


Short name for network 


Network name 
10.5.3.5a 





TLV 


3-? 


46 


Local time zone 


Time zone 
10.5.3.8 





TV 


2 


47 


Universal time and local time zone 


Time zone and time 
10.5.3.9 





TV 


8 


48 


LSA Identity 


LSA Identifier 
10.5.3.11 





TLV 


2-5 


49 


Network Daylight Saving Time 


Daylight Saving Time 
10.5.3.12 





TLV 


3 



9.4.19.1 



Full name for network 



This IE may be sent by the network. If this IE is sent, the contents of this IE indicate the "full length name of the 
network" that the network wishes the mobile station to associate with the MCC and MNC contained in the routing area 
identification of the current cell. 



9.4.19.2 



Short name for network 



This IE may be sent by the network. If this IE is sent, the contents of this IE indicate the "abbreviated name of the 
network" that the network wishes the mobile station to associate with the MCC and MNC contained in the routing area 
identification of the cell the MS is currently in. 
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9.4.19.3 



Local time zone 



This IE may be sent by the network. The mobile station should assume that this time zone applies to the routing area of 
the cell the MS is currently in. 

If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE 
Network Daylight Saving Time. 



9.4.19.4 



Universal time and local time zone 



This IE may be sent by the network. The mobile station should assume that this time zone applies to the routing area the 
MS is currently in. The mobile station shall not assume that the time information is accurate. 

If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE 
Network Daylight Saving Time. 

9.4.19.5 LSA Identity 

This IE may be sent by the network. The contents of this IE indicate the LSA identity of the serving cell. 

9.4.1 9.6 Network Daylight Saving Time 

This IE may be sent by the network. If this IE is sent, the contents of this IE indicates the value that has been used to 
adjust the local time zone. 

9.4.20 Service Request (lu mode only) 

This message is sent by the MS to transfer to establish logical association between the MS and the network. See 
table 9.4.20/3GPP TS 24.008. 

Message type: Service Request 

Significance: dual 

Direction: MS to network 

Table 9.4.20/3GPP TS 24.008: Contents of Service Request message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Service Request message identity 


IVIessage type 
10.4 


M 


V 


1 




Ciphering l<ey sequence number 


Ciphering key sequence number 
10.5.1.2 


M 


V 


1/2 




Service type 


Service type 
10.5.5.20 


M 


V 


1/2 




P-TMSI 


IVIobile station identity 
10.5.1.4 


M 


LV 


6 


32 


PDF context status 


PDP context status 
10.5.7.1 





TLV 


4 


35 


IVIBIVIS context status 


MBMS context status 
10.5.7.6 





TLV 


2-18 


36 


Uplinl< data status 


Uplink data status 
10.5.7.7 





TLV 


4 


D- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 
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9.4.20.1 PDP context status 

This IE shall be included by the MS. 

9.4.20.2 MBMS context status 

This IE shall be included by the MS, if it has MBMS contexts with an SM state different from PDP-INACTIVE. 

9.4.20.3 Uplink data status 

This IE may be included by the MS when the Service Type is set to "data". 

9.4.20.4 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.4.21 Service Accept (lu mode only) 

This message is sent by the network in response to a Service Request message. See table 9.4.21/3GPP TS 24.008. 
Message type: Service Accept 
Significance: dual 
Direction: network to MS 

Table 9.4.21/3GPP TS 24.008: Contents of Service Accept message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Service Accept message identity 


IVIessage type 
10.4 


M 


V 


1 


32 


PDP context status 


PDP context status 
10.5.7.1 





TLV 


4 


35 


IVIBIVIS context status 


MBMS context status 
10.5.7.6 





TLV 


2- 18 



9.4.21 .1 PDP context status 

This IE shall be included by the NW. 

9.4.21 .2 MBMS context status 

This IE shall be included by the network, if it has MBMS contexts for the MS with an SM state different from PDP- 
INACTIVE. 



9.4.22 Service Reject (lu mode only) 



This message is sent by the network to the MS in order to reject the Service request procedure. See table 9.4.22/3GPP 
TS 24.008. 

Message type: Service Reject 

Significance: dual 

Direction: network to MS 
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Table 9.4.22/3GPP TS 24.008: Contents of Service Reject message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Sl<ip indicator 


Skip indicator 
10.3.1 


M 


V 


1/2 




Service Reject message identity 


IVIessage type 
10.4 


M 


V 


1 




GMM cause 


GMM cause 
10.5.5.14 


M 


V 


1 


3A 


T3346 value 


GPRS timer 2 
10.5.7.4 





TLV 


3 



9.4.22.1 T3346 value 

This IE may be included when the general NAS level mobility management congestion control is active. 

9.5 GPRS Session Management Messages 
9.5.1 Activate PDP context request 

This message is sent by the MS to the network to request activation of a PDP context. 
See table 9.5.1/3GPP TS 24.008. 

Message type: ACTIVATE PDP CONTEXT REQUEST 

Significance: global 
Direction: MS to network 

Table 9.5.1/3GPP TS 24.008: ACTIVATE PDP CONTEXT REQUEST message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate PDP context request 
message identity 


Message type 
10.4 


M 


V 


1 




Requested NSAPI 


Network service access point identifier 
10.5.6.2 


M 


V 


1 




Requested LLC SAPI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 




Requested QoS 


Quality of service 
10.5.6.5 


M 


LV 


13-17 




Requested PDP address 


Packet data protocol address 
10.5.6.4 


M 


LV 


3-23 


28 


Access point name 


Access point name 
10.5.6.1 





TLV 


3-102 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


A- 


Request type 


Request type 
10.5.6.17 





TV 


1 


0- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 



9.5.1 .1 Access point name 

This IE is included in the message when the MS selects a specific external network to be connected to. 
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9.5.1.2 



Protocol configuration options 



This IE is included in the message when the MS wishes to transmit (protocol) data (e.g. configuration parameters, error 
codes or messages/events) to the network. 

This IE shall be included if the MS supports Network Requested Bearer Control procedures. 

9.5.1.3 Request type 

This IE is included in the message to indicate whether the PDP context request is for a handover from a non-3GPP 
access network or to activate a PDP context for emergency bearer services. 

9.5.1 .4 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.5.2 Activate PDP context accept 

This message is sent by the network to the MS to acknowledge activation of a PDP context. 
See table 9.5.2/3GPP TS 24.008. 

Message type: ACTIVATE PDP CONTEXT ACCEPT 

Significance: global 

Direction: network to MS 

Table 9.5.2/3GPP TS 24.008: ACTIVATE PDP CONTEXT ACCEPT message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate PDP context accept 
message identity 


IVIessage type 
10.4 


M 


V 


1 




Negotiated LLC SAPI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 




Negotiated QoS 


Quality of service 
10.5.6.5 


M 


LV 


13-17 




Radio priority 


Radio priority 
10.5.7.2 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


2B 


PDP address 


Packet data protocol address 
10.5.6.4 





TLV 


4-24 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


34 


Packet Flow Identifier 


Packet Flow Identifier 
10.5.6.11 





TLV 


3 


39 


SIVI cause 


SM cause 2 
10.5.6.6a 





TLV 


3 


B- 


Connectivity type 


Connectivity type 
10.5.6.19 





TV 


1 



9.5.2.1 



PDP address 



This IE shall be included by the network if the MS has requested the activation of a PDP context with the PDP type 
IPv4 or IPv6 or IPv4v6 and dynamic addressing. 
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9.5.2.2 



Protocol configuration options 



This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. This IE is also included to indicate the selected Bearer Control Mode to be 
applied for all active PDP contexts sharing the same PDP Address and APN. 



9.5.2.3 



Packet Flow Identifier 



This IE may be included if the network wants to indicate the Packet Flow Identifier associated to the PDP context. The 
network shall not include this IE if the MS has not indicated PEC procedure support in PEC feature mode field of MS 
Network Capability IE. 

If the MS has not indicated PEC procedure support, then it shall ignore this IE, if received. 

9.5.2.4 SM cause 

This IE shall be included if the network accepts the requested PDN connectivity with restrictions. 

9.5.2.5 Connectivity type 

The network shall include the connectivity type IE if: 

the network is configured to indicate when a PDN connection is a LIPA PDN connection; and 
the present PDN connection is a LIPA PDN connection. 

9.5.3 Activate PDP context reject 

This message is sent by the network to the MS to reject activation of a PDP context. 
See table 9.5.3/3GPP TS 24.008. 

Message type: ACTIVATE PDP CONTEXT REJECT 

Significance: global 

Direction: network to MS 

Table 9.5.3/3GPP TS 24.008: ACTIVATE PDP CONTEXT REJECT message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate PDP context reject 
message identity 


IVIessage type 
10.4 


M 


V 


1 




SM cause 


SM Cause 
10.5.6.6 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


37 


T3396 value 


GPRS timer 3 
10.5.7.4a 





TLV 


3 



9.5.3.1 



Protocol configuration options 



This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.3.2 T3396 value 

The network may include this IE if the SM cause is #26 "insufficient resources" or #27 "missing or unknown APN". 
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9.5.4 Activate Secondary PDP Context Request 

This message is sent by the MS to the network to request activation of an additional PDP context associated with the 
same PDP address and APN as an aheady active PDP context. See Table 9.5.4/3GPP TS 24.008. 

Message type: ACTIVATE SECONDARY PDP CONTEXT REQUEST 

Significance: global 

Direction: MS to network 

Table 9.5.4/3GPP TS 24.008: ACTIVATE SECONDARY PDP CONTEXT REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


y^ 3/2 




Activate secondary PDP context 
request message identity 


IVIessage type 
10.4 


M 


V 


1 




Requested NSAPI 


Network service access point identifier 
10.5.6.2 


M 


V 


1 




Requested LLC SAPI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 




Requested QoS 


Quality of service 
10.5.6.5 


M 


LV 


13-17 




Linl<ed Tl 


Linked Tl 
10.5.6.7 


M 


LV 


2-3 


36 


TFT 


Traffic Flow Template 
10.5.6.12 





TLV 


3-257 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


C- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 



9.5.4.1 TFT 

This IE shall be included if a linked PDP context without TFT has already been activated. 



9.5.4.2 



Protocol configuration options 



This IE is included in the message when the MS wishes to transmit (protocol) data (e.g. configuration parameters, error 
codes or messages/events) to the network. 

9.5.4.3 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.5.5 Activate Secondary PDP Context Accept 

This message is sent by the network to the MS to acknowledge activation of an additional PDP context associated with 
the same PDP address and APN as an already active PDP context. See Table 9.5.5/3GPP TS 24.008. 

Message type: ACTIVATE SECONDARY PDP CONTEXT ACCEPT 

Significance: global 

Direction: network to MS 
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Table 9.5.5/3GPP TS 24.008: ACTIVATE SECONDARY PDP CONTEXT ACCEPT message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate secondary PDP context 
accept message identity 


IVIessage type 
10.4 


M 


V 


1 




Negotiated LLC SAPI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 




Negotiated QoS 


Quality of service 
10.5.6.5 


M 


LV 


13-17 




Radio priority 


Radio priority 
10.5.7.2 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 


34 


Packet Flow Identifier 


Packet Flow Identifier 
10.5.6.11 





TLV 


3 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.5.1 



Packet Flow Identifier 



This IE may be included if the network wants to indicate the Packet Flow Identifier associated to the PDP context. The 
network shall not include this IE if the MS has not indicated PFC procedure support in PFC feature mode field of MS 
Network Capability IE. 

If the MS has not indicated PFC procedure support, then it shall ignore this IE, if received. 



9.5.5.2 



Protocol configuration options 



This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.6 Activate Secondary PDP Context Reject 

This message is sent by the network to the MS to reject activation of an additional PDP context associated with the 
same PDP address and APN as an already active PDP context. See Table 9.5.6/3GPP TS 24.008. 

Message type: ACTIVATE SECONDARY PDP CONTEXT REJECT 

Significance: global 

Direction: network to MS 

Table 9.5.6/3GPP TS 24.008: ACTIVATE SECONDARY PDP CONTEXT REJECT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate secondary PDP context 
reject message identity 


IVIessage type 
10.4 


M 


V 


1 




SIVI cause 


SM Cause 
10.5.6.6 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


37 


T3396 value 


GPRS timer 3 
10.5.7.4a 





TLV 


3 
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9.5.6.1 



Protocol configuration options 



This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.6.2 T3396 value 

The network may include this IE if the SM cause is #26 "insufficient resources". 

9.5.7 Request PDP context activation 

This message is sent by the network to the MS to initiate activation of a PDP context. 
See table 9.5.7/3GPP TS 24.008. 

Message type: REQUEST PDP CONTEXT ACTIVATION 

Significance: global 

Direction: network to MS 

Table 9.5.7/3GPP TS 24.008: REQUEST PDP CONTEXT ACTIVATION message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Request PDP context activation 
message identity 


IVIessage type 
10.4 


M 


V 


1 




Offered PDP address 


Packet data protocol address 
10.5.6.4 


M 


LV 


3-23 


28 


Access point name 


Access point name 
10.5.6.1 





TLV 


3-102 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.7.1 



Protocol configuration options 



This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.8 Request PDP context activation reject 

This message is sent by the MS to the network to reject initiation of a PDP context activation. 
See table 9.5.8/3GPP TS 24.008. 

Message type: REQUEST PDP CONTEXT ACTIVATION REJECT 

Significance: global 

Direction: MS to network 
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Table 9.5.8/3GPP TS 24.008: REQUEST PDP CONTEXT ACTIVATION REJECT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Request PDP context act. reject 
message identity 


IVIessage type 
10.4 


M 


V 


1 




SIVI cause 


SM cause 
10.5.6.6 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.8.1 



Protocol configuration options 



This IE is included in the message when the MS wishes to transmit (protocol) data (e.g. configuration parameters, error 
codes or messages/events) to the network. 

9.5.9 Modify PDP context request (Network to MS direction) 

This message is sent by the network to the MS to request modification of an active PDP context. See table 9.5.9/3GPP 
TS 24.008. 

Message type: MODIFY PDP CONTEXT REQUEST (NETWORK TO MS DIRECTION) 

Significance: global 

Direction: network to MS 

Table 9.5.9/3GPP TS 24.008: MODIFY PDP CONTEXT REQUEST (Network to MS direction) message 

content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




IVIodify PDP context request 
message identity 


IVIessage type 
10.4 


M 


V 


1 




Radio priority 


Radio priority 
10.5.7.2 


M 


V 


1/2 




Spare half octet 


Spare half octet 
10.5.1.8 


M 


V 


1/2 




Requested LLC SAPI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 




New QoS 


Quality of service 
10.5.6.5 


M 


LV 


13-17 


2B 


PDP address 


Packet data protocol address 
10.5.6.4 





TLV 


4-24 


34 


Packet Flow Identifier 


Packet Flow Identifier 
10.5.6.11 





TLV 


3 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


36 


TFT 


Traffic Flow Template 
10.5.6.12 





TLV 


3-257 



9.5.9.1 



PDP address 



If the MS requested external PDP address allocation at PDP context activation via an APN and this was confirmed by 
the network in the ACTIVATE PDP CONTEXT ACCEPT message, then the network shall include the PDP address IE 
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in the MODIFY PDP CONTEXT REQUEST message once the address has been actually allocated, in order to update 
the PDP context in the MS. 



9.5.9.2 



Packet Flow Identifier 



This IE may be included if the network wants to indicate the Packet Flow Identifier associated to the PDP context. The 
network shall not include this IE if the MS has not indicated PEC procedure support in PEC feature mode field of MS 
Network Capability IE. 

If this IE is not included, the MS shall keep the old Packet Elow Identifier value. If the MS has not indicated PEC 
procedure support, then it shall ignore this IE, if received. 



9.5.9.3 



Protocol configuration options 



This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. This IE is also included to indicate the selected Bearer Control Mode to be 
apphed. 



9.5.9.4 



TFT 



This IE is included in the message to provide the MS with uplink and downlink packet filters when the protocol 
configuration options information element indicates the selected Bearer Control Mode 'MS/NW. 

9.5.1 Modify PDP context request (MS to network direction) 

This message is sent by the MS to the network to request modification of an active PDP context. See table 9.5. 10/3GPP 
TS 24.008. 

Message type: MODIFY PDP CONTEXT REQUEST (MS TO NETWORK DIRECTION) 

Significance: global 
Direction: MS to network 

Table 9.5.1 0/3GPP TS 24.008: MODIFY PDP CONTEXT REQUEST (MS to network direction) message 

content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




IVIodify PDP context request 
message identity 


IVlessage type 
10.4 


M 


V 


1 


32 


Requested LLC SARI 


LLC service access point identifier 
10.5.6.9 





TV 


2 


30 


Requested new QoS 


Quality of service 
10.5.6.5 





TLV 


14-18 


31 


New TFT 


Traffic Flow Template 
10.5.6.12 





TLV 


3-257 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


C- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 



9.5.1 0.1 Requested LLC SAPI 

This IE may be included in the message to request a new LLC SAPI if a new QoS is requested. 
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9.5.1 0.2 Requested new QoS 

This IE may be included in the message to request a modification of the QoS. 



9.5.10.3 



New TFT 



This IE may be included in the message to request a new TFT or modification of an existing TFT or transfer extra 
parameters to the network (e.g. the Authorization Token; see 3GPP TS 24.229 [95]). 

9.5.10.4 Protocol configuration options 

This IE is included in the message when the MS wishes to transmit (protocol) data (e.g. configuration parameters, error 
codes or messages/events) to the network. 

9.5.10.5 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.5.1 1 Modify PDP context accept (MS to network direction) 

This message is sent by the MS to the network to acknowledge the modification of an active PDP context. See 
table 9.5.11/3GPP TS 24.008. 

Message type: MODIFY PDP CONTEXT ACCEPT (MS TO NETWORK DIRECTION) 

Significance: global 

Direction: MS to network 

Table 9.5.11/3GPP TS 24.008: MODIFY PDP CONTEXT ACCEPT (MS TO NETWORK DIRECTION) 

message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




IVIodify PDP context accept 
message identity 


IVIessage type 
10.4 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.1 1 .1 Protocol configuration options 

This IE is included in the message when the MS wishes to transmit (protocol) data (e.g. configuration parameters, error 
codes or messages/events) to the network. 

9.5.12 Modify PDP context accept (Network to MS direction) 

This message is sent by the network to the MS to acknowledge the modification of an active PDP context. See 
table 9.5.12/3GPP TS 24.008. 

Message type: MODIFY PDP CONTEXT ACCEPT (NETWORK TO MS DIRECTION) 

Significance: global 

Direction: Network to MS 
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Table 9.5.1 2/3GPP TS 24.008: MODIFY PDP CONTEXT ACCEPT (NETWORK to MS direction) message 

content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


y^ 3/2 




IVIodify PDP context accept 
message identity 


IVIessage type 
10.4 


M 


V 


1 


30 


Negotiated QoS 


Quality of service 
10.5.6.5 





TLV 


14-18 


32 


Negotiated LLC SAPI 


LLC service access point identifier 
10.5.6.9 





TV 


2 


8 


New radio priority 


Radio priority 
10.5.7.2 





TV 


1 


34 


Packet Flow Identifier 


Packet Flow Identifier 
10.5.6.11 





TLV 


3 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.12.1 Negotiated QoS 

This IE is included in the message if the network assigns a new QoS. 

9.5.1 2.2 Negotiated LLC SAPI 

This IE is included in the message if the network assigns a new LLC SAPI. 

9.5.1 2.3 New radio priority 

This IE is included in the message only if the network modifies the radio priority. 



9.5.12.4 



Packet Flow Identifier 



This IE may be included if the network wants to indicate the Packet Flow Identifier associated to the PDP context. The 
network shall not include this IE if the MS has not indicated PEC procedure support in PEC feature mode field of MS 
Network Capability IE. 

If this IE is not included, the MS shall keep the old Packet Flow Identifier value. If the MS has not indicated PEC 
procedure support, then it shall ignore this IE, if received. 

9.5.12.5 Protocol configuration options 

This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.13 Modify PDP Context Reject 

This message is sent by the network or the MS to reject a modification of an active PDP context. See Table 
9.5.13/3GPPTS 24.008. 

Message type: MODIFY PDP CONTEXT REJECT 

Significance: global 

Direction: both 
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Table 9.5.1 3/3GPP TS 24.008: MODIFY PDP CONTEXT REJECT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




IVIodify PDP Context Reject 


IVIessage type 
10.4 


M 


V 


1 




SIVI cause 


SM Cause 
10.5.6.6 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


37 


T3396 value 


GPRS timer 3 
10.5.7.4a 





TLV 


3 



9.5.13.1 Protocol configuration options 

This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.13.2 T3396 value 

The network may include this IE if the SM cause is #26 "insufficient resources". 

9.5.14 Deactivate PDP context request 

This message is sent to request deactivation of an active PDP context or an active MBMS context. See 
table 9.5.14/3GPP TS 24.008. 

Message type: DEACTIVATE PDP CONTEXT REQUEST 

Significance: global 

Direction: both 

Table 9.5.1 4/3GPP TS 24.008: DEACTIVATE PDP CONTEXT REQUEST message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Deactivate PDP context request 
message identity 


IVIessage type 
10.4 


M 


V 


1 




SM cause 


SM cause 
10.5.6.6 


M 


V 


1 


9- 


Tear down indicator 


Tear down indicator 
10.5.6.10 





TV 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


35 


IVIBMS protocol configuration 
options 


MBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 



9.5.14.1 



Tear down indicator 



This IE is included in the message in order to indicate whether only the PDP context associated with this specific TI or 
all active PDP contexts sharing the same PDP address and APN as the PDP context associated with this specific TI shall 
be deactivated. 

If this IE is received for an MBMS context, it shall be ignored by the receiver. 
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9.5.14.2 Protocol configuration options 

This IE is included in the message when the MS or the network wishes to transmit (protocol) data (e.g. configuration 
parameters, error codes or messages/events) to the peer entity. 

If this IE is received for an MBMS context, it shall be ignored by the receiver. 

9.5.14.3 MBMS protocol configuration options 

This IE is included in the message when the MS or the network wishes to transmit MBMS bearer related (protocol) data 
(e.g. configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 

If the IE is received for a PDP context, it shall be ignored by the receiver. 

9.5.15 Deactivate PDP context accept 

This message is sent to acknowledge deactivation of the PDP context requested in the corresponding Deactivate PDP 
context request message. See table 9.5.15/3GPP TS 24.008. 

Message type: DEACTIVATE PDP CONTEXT ACCEPT 

Significance: global 

Direction: both 

Table 9.5.1 5/3GPP TS 24.008: DEACTIVATE PDP CONTEXT ACCEPT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Deactivate PDP context accept 
message identity 


IVIessage type 
10.4 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 


35 


IVIBMS protocol configuration 
options 


IVIBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 



9.5.15.1 Protocol configuration options 

This IE is included in the message when the MS or the network wishes to transmit (protocol) data (e.g. configuration 
parameters, error codes or messages/events) to the peer entity. 

If this IE is received for an MBMS context, it shall be ignored by the receiver. 

9.5.15.2 MBMS protocol configuration options 

This IE is included in the message when the MS or the network wishes to transmit MBMS bearer related (protocol) data 
(e.g. configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 

If the IE is received for a PDP context, it shall be ignored by the receiver. 

9.5.15a Request Secondary PDP Context Activation 

This message is sent by the network to the MS to request activation of a secondary PDP context. 
See table 9.5.15a/3GPP TS 24.008. 

Message type: REQUEST SECONDARY PDP CONTEXT ACTIVATION 

Significance: global 
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Direction: 



network to MS 



Table 9.5.1 5a/3GPP TS 24.008: REQUEST SECONDARY PDP CONTEXT ACTIVATION message 

content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Request secondary PDP context 
activation message identity 


Message type 
10.4 


M 


V 


1 




Required QoS 


Quality of service 
10.5.6.5 


M 


LV 


13-17 




Linl<ed Tl 


Linked Tl 
10.5.6.7 


M 


LV 


2-3 


36 


TFT 


Traffic Flow Template 
10.5.6.12 





TLV 


3-257 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.15.1a TFT 

This IE shall be included if a linked PDP context without TFT has already been activated. This IE provides the MS with 
uplink and downlink packet filters. 

9.5.15.2a Protocol configuration options 

This IE is included in the message when the network wishes to transmit (protocol) data (e.g. configuration parameters, 
error codes or messages/events) to the MS. 

9.5.15b Request Secondary PDP Context Activation Reject 

This message is sent by the MS to the network to reject the request of a secondary PDP context activation. 
See table 9.5.15b/3GPP TS 24.008. 

Message type: REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT 

Significance: global 
Direction: MS to network 

Table 9.5.1 5b/3GPP TS 24.008: REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT 

message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Request secondary PDP context 
activation reject message identity 


IVlessage type 
10.4 


M 


V 


1 




SIVI cause 


SM cause 
10.5.6.6 


M 


V 


1 


27 


Protocol configuration options 


Protocol configuration options 
10.5.6.3 





TLV 


3-253 



9.5.1 5.1 b Protocol configuration options 

This IE is included in the message when the MS wishes to transmit (protocol) data (e.g. configuration parameters, error 
codes or messages/events) to the network. 
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9.5.16 Void 
9.5.16a Notification 

This message is sent by the network to inform the MS about events which are relevant for the upper layer using the PDP 
context or having requested a session management procedure. See table 9.5.16a/3GPP TS 24.008. 

Message type: NOTIFICATION 

Significance: local 

Direction: network to MS 

Table 9.5.1 6a/3GPP TS 24.008: NOTIFICATION message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Notification message identity 


IVIessage type 
10.4 


M 


V 


1 




Notification indicator 


Notification indicator 
10.5.6.18 


M 


LV 


2 



9.5.17 Void 

9.5.18 Void 

9.5.19 Void 

9.5.20 Void 

9.5.21 SM Status 

This message is sent by the network or the MS to pass information on the status of the indicated context and report 
certain error conditions (eg. as listed in clause 8). See table 9.5.21/3GPP TS 24.008. 

Message type: SM Status 

Significance: local 

Direction: both 

Table 9.5.21/3GPP TS 24.008: SM STATUS message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




SIVI Status message identity 


IVIessage type 
10.4 


M 


V 


1 




SIVI Cause 


SM Cause 
10.5.6.6 


M 


V 


1 
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9.5.22 Activate MBMS Context Request 



This message is sent by the MS to the network as an explicit response to a Request MBMS Context Activation message 
See table 9.5.22/3GPP TS 24.008. 

Message type: ACTIVATE MBMS CONTEXT REQUEST 

Significance: global 

Direction: MS to network 

TABLE 9.5.22 : ACTIVATE MBMS CONTEXT REQUEST message content 



lEI 


Information Element 


Type/ 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate MBMS context request 
message identity 


Message type 
10.4 


M 


V 


1 




Requested MBMS NSAPI 


Enhanced Network service access 
point identifier 10.5.6.16 


M 


V 


1 




Requested LLC SARI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 




Supported MBMS bearer 
capabilities 


MBMS bearer capabilities 
10.5.6.14 


M 


LV 


2-3 




Requested multicast address 


Packet data protocol address 
10.5.6.4 


M 


LV 


3-23 




Access point name 


Access point name 
10.5.6.1 


M 


LV 


2-101 


35 


MBMS protocol configuration 
options 


MBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 


C- 


Device properties 


Device properties 
10.5.7.8 





TV 


1 



NOTE: The MBMS NSAPI will be used in lu mode when the network chooses a point-to-point MBMS bearer for 
the transfer of MBMS data in the user plane. 

9.5.22.1 MBMS protocol configuration options 

This IE is included in the message when the MS wishes to transmit MBMS bearer related (protocol) data (e.g. 
configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 

9.5.22.2 Device properties 

This IE shall be included if the MS is configured for NAS signalling low priority. 

9.5.23 Activate MBMS Context Accept 

This message is sent by the network to the MS to acknowledge activation of an MBMS context. 
See table 9.5.23/3GPP TS 24.008. 

Message type: ACTIVATE MBMS CONTEXT ACCEPT 

Significance: global 

Direction: network to MS 
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TABLE 9.5.23 : ACTIVATE MBMS CONTEXT ACCEPT message content 



lEI 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate IVIBIVIS context accept 
message identity 


IVlessage type 
10.4 


M 


V 


1 




Temporary IVIobile Group Identity 


Temporary Mobile Group Identity 
10.5.6.13 


M 


LV 


4-7 




Negotiated LLC SAPI 


LLC service access point identifier 
10.5.6.9 


M 


V 


1 


35 


IVIBIVIS protocol configuration 
options 


IVIBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 



9.5.23.1 MBMS protocol configuration options 

This IE is included in the message when the network wishes to transmit MBMS bearer related (protocol) data (e.g. 
configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 

9.5.24 Activate MBMS Context Reject 

This message is sent by the network to the MS to reject activation of a MBMS context. 
See table 9.5.24/3GPP TS 24.008. 

Message type: ACTIVATE MBMS CONTEXT REJECT 

Significance: global 

Direction: network to MS 

TABLE 9.5.24 : ACTIVATE MBMS CONTEXT REJECT message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Activate IVIBMS context reject 
message identity 


Message type 
10.4 


M 


V 


1 




SM cause 


SM Cause 
10.5.6.6 


M 


V 


1 


35 


MBMS protocol configuration 
options 


MBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 


37 


T3396 value 


GPRS timer 3 
10.5.7.4a 





TLV 


3 



9.5.24.1 MBMS protocol configuration options 

This IE is included in the message when the network wishes to transmit MBMS bearer related (protocol) data (e.g. 
configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 

9.5.24.2 T3396 value 

The network may include this IE if the SM cause #26 "insufficient resources" or is #27 "missing or unknown APN". 
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9.5.25 Request MBMS Context Activation 

This message is sent by the network to the MS to initiate activation of an MBMS context. 
See table 9.5.25/3GPP TS 24.008. 

Message type: REQUEST MBMS CONTEXT ACTIVATION 

Significance: global 

Direction: network to MS 

TABLE 9.5.25 : REQUEST MBMS CONTEXT ACTIVATION message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Request IVIBIVIS context activation 
message identity 


IVIessage type 
10.4 


M 


V 


1 




Linl<ed NSAPI 


Network service access point identifier 
10.5.6.2 


M 


V 


1 




Offered Multicast address 


Packet data protocol address 
10.5.6.4 


M 


LV 


3-23 




Access point name 


Access point name 
10.5.6.1 


M 


LV 


2-101 


35 


IVIBMS protocol configuration 
options 


IVIBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 



9.5.25.1 



Linked NSAPI 



This IE is included in the message to allow the MS to associate the MBMS context with the PDP context over which the 
IGMP/MLD join message was sent. 

9.5.25.2 MBMS protocol configuration options 

This IE is included in the message when the network wishes to transmit MBMS bearer related (protocol) data (e.g. 
configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 

9.5.26 Request MBMS Context Activation Reject 

This message is sent by the MS to the network to reject initiation of an MBMS context activation. 
See table 9.5.26/3GPP TS 24.008. 

Message type: REQUEST MBMS CONTEXT ACTIVATION REJECT 

Significance: global 

Direction: MS to network 
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TABLE 9.5.26 : REQUEST MBMS CONTEXT ACTIVATION REJECT message content 



IE! 


Information Element 


Type/Reference 


Presence 


Format 


Length 




Protocol discriminator 


Protocol discriminator 
10.2 


M 


V 


1/2 




Transaction identifier 


Transaction identifier 
10.3.2 


M 


V 


1/2-3/2 




Request IVIBIVIS context act. reject 
message identity 


IVIessage type 
10.4 


M 


V 


1 




SIVI cause 


SM Cause 
10.5.6.6 


M 


V 


1 


35 


IVIBIVIS protocol configuration 
options 


MBMS protocol configuration options 
10.5.6.15 





TLV 


3-253 



9.5.26.1 MBMS protocol configuration options 

This IE is included in the message when the MS wishes to transmit MBMS bearer related (protocol) data (e.g. 
configuration parameters, error codes or messages/events) to the peer entity for an MBMS context. 



10 General message format and information elements 
coding 

The figures and text in this clause describe the Information Elements contents. 

10.1 Overview 

Within the Layer 3 protocols defined in 3GPP TS 24.008, every message is a standard L3 message as defined in 3GPP 
TS 24.007 [20]. This means that the message consists of the following parts: 

a) protocol discriminator; 

b) transaction identifier; 

c) message type; 

d) other information elements, as required. 

This organization is illustrated in the example shown in figure 10. 1/3GPP TS 24.008. 



Transaction identifier 
or Skip Indicator 



Protocol discriminator 



+- 

I 
+- 

I 
+- 



Message type 
Other information elements as required 



octet 1 

octet 2 
etc . . . 



Figure 10.1/3GPP TS 24.008 General message organization example 

Unless specified otherwise in the message descriptions of clause 9, a particular information element shall not be present 
more than once in a given message. 

The term "default" implies that the value defined shall be used in the absence of any assignment, or that this value 
allows negotiation of alternative values in between the two peer entities. 
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When a field extends over more than one octet, the order of bit values progressively decreases as the octet number 
increases. The least significant bit of the field is represented by the lowest numbered bit of the highest numbered octet 
of the field. 

10.2 Protocol Discriminator 

The Protocol Discriminator (PD) and its use are defined in 3GPP TS 24.007 [20]. 

1 0.3 Skip indicator and transaction identifier 

10.3.1 Skip indicator 

Bits 5 to 8 of the first octet of every Mobility Management message and GPRS MobilityManagement message contains 
the skip indicator. A message received with skip indicator different from 0000 shall be ignored. A message received 
with skip indicator encoded as 0000 shall not be ignored (unless it is ignored for other reasons). A protocol entity 
sending a Mobility Management message or a GPRS Mobility Management message shall encode the skip indicator 
as 0000. 

10.3.2 Transaction identifier 

Bits 5 to 8 of the first octet of every message belonging to the protocols "Call Control; call related SS messages" and 
"Session Management"contain the transaction identifier (TI). The transaction identifier and its use are defined in 3GPP 
TS 24.007 [20]. 

For the session management protocol, the extended TI mechanism may be used (see 3GPP TS 24.007 [20]). 

For the call control protocol, the extended TI mechanism shall be supported for the piupose of protocol error handling 
as specified in subclause 8.3.1 



10.4 IVI ess age Type 



The message type IE and its use are defined in 3GPP TS 24.007 [20]. Tables 10.3/3GPP TS 24.008, 

10.4/3GPP TS 24.008, and 10.4a/3GPP TS 24.008 define the value part of the message type IE used in the Mobility 

Management protocol, the Call Control protocol, and Session management protocol. 
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Table 10.2/3GPP TS 24.008: Message types for Mobility Management 



8 7 6 


5 


4 


3 


2 


1 




X X 





- 


- 


- 


- 


Registration messages: 















1 


- IMSI DETACH INDICATION 












1 





- LOCATION UPDATING ACCEPT 









1 








- LOCATION UPDATING REJECT 






1 











- LOCATION UPDATING REOUEST 


X X 


1 


- 


- 


- 


- 


Security messages: 















1 


- AUTHENTICATION REJECT 












1 





- AUTHENTICATION REQUEST 









1 








- AUTHENTICATION RESPONSE 








1 








- AUTHENTICATION FAILURE 

















- IDENTITY REOUEST 














1 


- IDENTITY RESPONSE 











1 





- TMSI REALLOCATION COMMAND 











1 


1 


- TMSI REALLOCATION COMPLETE 


X X 1 





- 


- 


- 


- 


Connection management messages: 















1 


- CM SERVICE ACCEPT 












1 





- CM SERVICE REJECT 












1 


1 


- CM SERVICE ABORT 









1 








- CM SERVICE REQUEST 









1 





1 


-CM SERVICE PROMPT 









1 


1 





- Reserved (see NOTE) 






1 











- CM RE-ESTABLISHMENT REQUEST 






1 








1 


- ABORT 


X X 1 


1 


- 


- 


- 


- 


Miscellaneous messages: 


















-MM NULL 















1 


- MM STATUS 












1 





- MM INFORMATION 



NOTE: This value was allocated but never used in earlier phases of the protocol. 

When the radio connection started with a core network node of earlier than R99, bit 8 shall be set to and bit 7 is 
reserved for the send sequence number in messages sent from the mobile station. In messages sent from the network, 
bits 7 and 8 are coded with a "0". See 3GPP TS 24.007 [20]. 

When the radio connection started with a core network node of R'99 or later, bits 7 and 8 are reserved for the send 
sequence number in messages sent from the mobile station. In messages sent from the network, bits 7 and 8 are coded 
with a "0". See 3GPP TS 24.007 [20]. 
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Table 10.3/3GPP TS 24.008: Message types for Call Control and call related SS messages 



8 7 6 


5 


4 


3 


2 






X X 

















escape to nationally specific 
message types; see 1) below 


X X 





- 


- 


- 




Call establishment messages: 

















- ALERTING 






1 











-CALL CONFIRMED 












1 





- CALL PROCEEDING 









1 


1 




- CONNECT 






1 


1 


1 




- CONNECT ACKNOWLEDGE 






1 


1 


1 





-EMERGENCY SETUP 












1 




- PROGRESS 









1 








- CC-ESTABLISHMENT 









1 


1 





- CC-ESTABLISHMENT CONFIRMED 






1 





1 




- RECALL 






1 










- START CC 









1 







- SETUP 


X X 


1 


- 


- 


- 




Call information phase messages: 









1 


1 




- MODIFY 






1 


1 


1 




-MODIFY COMPLETE 












1 




- MODIFY REJECT 


















- USER INFORMATION 






1 











-HOLD 






1 










- HOLD ACKNOWLEDGE 






1 





1 





- HOLD REJECT 






1 


1 








- RETRIEVE 






1 


1 







- RETRIEVE ACKNOWLEDGE 






1 


1 


1 





- RETRIEVE REJECT 


X X 1 





- 


- 


- 




Call clearing messages: 









1 







- DISCONNECT 






1 


1 







- RELEASE 






1 





1 





- RELEASE COMPLETE 


X X 1 


1 


- 


- 


- 




Miscellaneous messages: 






1 










- CONGESTION CONTROL 






1 


1 


1 





- NOTIFY 






1 


1 







- STATUS 









1 








- STATUS ENOUIRY 









1 







- START DTMF 

















- STOP DTMF 












1 





- STOP DTMF ACKNOWLEDGE 









1 


1 





- START DTMF ACKNOWLEDGE 









1 


1 


1 


- START DTMF REJECT 






1 





1 





- FACILITY 



1): When used, the message type is defined in the following octet(s), according to the national specification. 

When the radio connection started with a core network node of eariier than R99, bit 8 shall be set to and bit 7 is 
reserved for the send sequence number in messages sent from the mobile station. In messages sent from the network, 
bits 7 and 8 are coded with a "0". See 3GPP TS 24.007 [20]. 

When the radio connection started with a core network node of R'99 or later, bits 7 and 8 are reserved for the send 
sequence number in messages sent from the mobile station. In messages sent from the network, bits 7 and 8 are coded 
with a "0". See 3GPP TS 24.007 [20]. 
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Table 10.4/3GPP TS 24.008: Message types for GPRS mobility management 



Bits 
















8 


7 


6 


5 


4 


3 


2 


1 










- 


- 


- 


- 


- 


- 


Mobility management messages 

























Attach request 




















1 





Attach accept 




















1 




Attach complete 

















1 








Attach reject 

















1 







Detach request 

















1 


1 





Detach accept 














1 











Routing area update request 














1 










Routing area update accept 














1 





1 





Routing area update complete 














1 





1 




Routing area update reject 














1 


1 








Service Request 














1 


1 







Service Accept 














1 


1 


1 





Service Reject 

























P-TMSI reallocation command 
























P-TMSI reallocation complete 



















1 





Authentication and ciphering req 



















1 




Authentication and ciphering resp 
















1 








Authentication and ciphering rej 













1 


1 








Authentication and ciphering failure 
















1 







Identity request 
















1 


1 





Identity response 








1 

















GMM status 








1 
















GMM information 
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Table 10.4a/3GPP TS 24.008: Message types for GPRS session management 



Bits 

8 7 6 5 4 3 2 1 

1 ----- - 

10 1 

10 10 

10 11 

10 10 

10 10 1 

10 110 

10 111 

10 10 

10 10 1 

10 10 10 

10 10 11 

10 110 

10 110 1 

10 1110 

10 1111 

10 10 

10 10 1 

10 10 10 

10 10 11 

10 10 10 

10 10 10 1 

10 10 110 

10 10 111 

10 110 

10 110 1 

10 110 10 

10 110 11 

10 1110 

10 1110 1 



Session management messages 

Activate PDP context request 
Activate PDP context accept 
Activate PDP context reject 

Request PDP context activation 

Request PDP context activation rej. 

Deactivate PDP context request 

Deactivate PDP context accept 

IVIodify PDP context request{Network to IVIS direction) 

IVIodify PDP context accept (IVIS to networl< direction) 

IVIodify PDP context request{IVIS to network direction) 

Modify PDP context accept (Network to IVIS direction) 

IVIodify PDP context reject 

Activate secondary PDP context request 
Activate secondary PDP context accept 
Activate secondary PDP context reject 



Reserved: was allocated in 
Reserved: was allocated in 
Reserved: was allocated in 
Reserved: was allocated in 
Reserved: was allocated in 

SM Status 



earlier phases of the protocol 
earlier phases of the protocol 
earlier phases of the protocol 
earlier phases of the protocol 
earlier phases of the protocol 



Activate IVIBMS Context Request 
Activate IVIBMS Context Accept 
Activate MBMS Context Reject 
Request MBMS Context Activation 
Request MBMS Context Activation Reject 

Request Secondary PDP Context Activation 
Request Secondary PDP Context Activation Reject 

Notification 



10.5 Other information elements 

The different formats (V, LV, T, TV, TLV) and the four categories of information elements (type 1, 2, 3, and 4) are 
defined in 3GPP TS 24.007 [20]. 

The first octet of an information element in the non-imperative part contains the lEI of the information element. If this 
octet does not correspond to an lEI known in the message, the receiver shall determine whether this IE is of type 1 or 2 
(i.e. it is an information element of one octet length) or an IE of type 4 (i.e. that the next octet is the length indicator 
indicating the length of the remaining of the information element) (see 3GPP TS 24.007 [20]). 

This allows the receiver to jump over unknown information elements and to analyse any following information 
elements. 

The information elements which are common for at least two of the three protocols Radio Resources management. 
Mobility Management and Call Control, are listed in subclause 10.5.1. 

The information elements for the protocols Mobility Management and Call Control are listed in subclauses 10.5.3 and 
10.5.4 respectively. Default information element identifiers are listed in annex K. 
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NOTE: Different information elements may have the same default information element identifier if they belong to 
different protocols. 

The descriptions of the information element types in subclauses 10.5.1, 10.5.3, and 10.5.4 are organized in alphabetical 
order of the IE types. Each IE type is described in one subclause. 

The subclause may have an introduction: 

possibly explaining the purpose of the IE; 

possibly describing whether the IE belongs to type 1, 2, 3, 4 or 5; 

possibly indicating the length that the information element has if it is either type 5 or if it is used in format TV 
(type 1 and 3) or TLV (type 4). 

A figure of the subclause defines the structure of the IE indicating: 

possibly the position and length of the lEI. (However it depends on the message in which the IE occurs whether 
the IE contains an lEL); 

the fields the IE value part is composed of; 

possibly the position and length of the length indicator. (However it depends on the IE type whether the IE 
contains a length indicator or not.); 

possibly octet numbers of the octets that compose the IE (see clause a) below). 

Finally, the subclause contains tables defining the structure and value range of the fields that compose the IE value part. 
The order of appearance for information elements in a message is defined in clause 9. 

The order of the information elements within the imperative part of messages has been chosen so that information 
elements with 1/2 octet of content (type 1) go together in succession. The first type 1 information element occupies bits 
1 to 4 of octet N, the second bits 5 to 8 of octet N, the third bits 1 to 4 of octet N + 1 etc. If the number of type 1 
information elements is odd then bits 5 to 8 of the last octet occupied by these information elements contains a spare 
half octet IE in format V. 

Where the description of information elements in the present document contains bits defined to be "spare bits", these 
bits shall set to the indicated value (0 or 1) by the sending side, and their value shall be ignored by the receiving side. 
With few exceptions, spare bits are indicated as being set to "0" in 3GPP TS 24.008. 

10.5.1 Common information elements. 
10.5.1.1 Cellidentity 

The purpose of the Cell Identity information element is to identify a cell within a location area. 

The Cell Identity information element is coded as shown in figure 10.5. 1/3GPP TS 24.008 and table 10.5.1/3GPP TS 
24.008. 

The Cell Identity is a type 3 information element with 3 octets length. 



octet 1 
octet 2 
octet 3 
Figure 10.5.1/3GPP TS 24.008 Cell WenWy information element 



8 


7 


6 5 4 3 


2 


1 


1 Cell Identity lEI 


CI value 


CI value (continued) 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



398 



ETSI TS 124 008 V1 0.1 0.0 (2013-04) 



Table 10.5.1/3GPP TS 24.008: Cell Identity information element 



CI value, Cell identity value (octet 2 and 3) 

In the CI value field bit 8 of octet 2 is the most significant bit and bit 1 of octet 3 the 
least significant bit. 

The coding of the cell identity is the responsibility of each administration. Coding 
using full hexadecimal representation may be used. 
The cell identity consists of 2 octets. 



10.5.1 .2 Ciphering Key Sequence Number 

In a GSM authentication challenge, the purpose of the Ciphering Key Sequence Number information element is to make 
it possible for the network to identify the ciphering key Kc which is stored in the mobile station without invoking the 
authentication procedure. 

The ciphering key sequence number is allocated by the network and sent with the AUTHENTICATION REQUEST or 
AUTHENTICATION AND CIPHERING REQUEST message to the mobile station where it is stored together with the 
calculated keys, e.g. Kc, CK, IK, Kci28. 

The Ciphering Key Sequence Number information element is coded as shown in figure 10.5.2/3GPP TS 24.008 and 
table 10.5.2/3GPP TS 24.008. 

In a UMTS authentication challenge, the purpose of the Ciphering Key Sequence Number information element is to 
make it possible for the network to identify the ciphering key CK and integrity key IK which are stored in the MS 
without invoking the authentication procedure. CK and IK form a Key Set Identifier (KSI) (see 3GPP TS 33.102 [5a]) 
which is encoded the same as the CKSN and is therefore included in the CKSN field. 

The ciphering key sequence number is a type 1 information element. 



octet 1 



Figure 10.5.2/3GPP TS 24.008 Ciphering Key Sequence Number information element 
Table 10.5.2/3GPP TS 24.008: Ciphering Key Sequence Number information element 



Ciphering Key 
Sequence Number 
lEI 



spare 


key sequence 



Key sequence (octet 1) 


Bits 
3 2 1 





through 

1 1 


Possible values for the ciphering key 
sequence number 


1 1 1 


No key is available (MS to network); 
Reserved (network to MS) 



10.5.1.3 



Location Area Identification 



The purpose of the Location Area Identification information element is to provide an unambiguous identification of 
location areas within the area covered by the 3GPP system. 

The Location Area Identification information element is coded as shown in figure 10.5.3/3GPP TS 24.008 and 
table 10.5.3/3GPP TS 24.008. 
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The Location Area Identification is a type 3 information element with 6 octets length. 



Location Area Identification 1 El 


MCC digit 2 


MCC digit 1 


MNCdigitS 


MCC digit 3 


l\/INCdigit2 


MNC digit 1 


LAC 


LAC (continued) 



octet 1 
octet 2 
octet 3 
octet 4 
octet 5 
octet 6 
Figure 10.5.3/3GPP TS 24.008 Location Area Identification information element 
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Table 10.5.3/3GPP TS 24.008: Location Area Identification information element 



MCC, Mobile country code (octet 2 and 3) 

The MCC field is coded as in ITU-T Rec. E212, Annex A. 

If the LAI is deleted the MCC and MNC shall take the value from the deleted LAI. 

In abnormal cases, the MCC stored in the mobile station can contain elements not 
in the set {0, 1 ... 9}. In such cases the mobile station should transmit the stored 
values using full hexadecimal encoding. When receiving such an MCC, the network 
shall treat the LAI as deleted. 

MNC, Mobile network code (octet 3 bits 5 to 8, octet 4) 

The coding of this field is the responsibility of each administration but BCD coding 
shall be used. The MNC shall consist of 2 or 3 digits. For PCS 1 900 for NA, Federal 
regulation mandates that a 3-digit MNC shall be used. However a network operator 
may decide to use only two digits in the MNC in the LAI over the radio interface. In 
this case, bits 5 to 8 of octet 3 shall be coded as "1111 ". Mobile equipment shall 
accept LAI coded in such a way. 

NOTE 1 : In earlier versions of this protocol, the possibility to use a one digit MNC 
in LAI was provided on the radio interface. However as this was not used 
this possibility has been deleted. 

NOTE 2: In earlier versions of this protocol, bits 5 to 8 of octet 3 were coded as 
"1111". Mobile equipment compliant with these earlier versions of the 
protocol may be unable to understand the 3-digit MNC format of the LAI, 
and therefore unable to register on a network broadcasting the LAI in this 
format. 

In abnormal cases, the MNC stored in the mobile station can have: 

- digit 1 or 2 not in the set {0, 1 ... 9}, or 

- digit 3 not in the set {0, 1 ... 9, F} hex. 

In such cases the mobile station shall transmit the stored values using full 
hexadecimal encoding. When receiving such an MNC, the network shall treat the 
LAI as deleted. 

The same handling shall apply for the network, if a 3-digit MNC is sent by the 
mobile station to a network using only a 2-digit MNC. 

LAC, Location area code (octet 5 and 6) 

In the LAC field bit 8 of octet 5 is the most significant bit and bit 1 of octet 6 the 

least significant bit. 

The coding of the location area code is the responsibility of each administration 

except that two values are used to mark the LAC, and hence the LAI, as deleted. 

Coding using full hexadecimal representation may be used. The location area code 

consists of 2 octets. 

If a LAI has to be deleted then all bits of the location area code shall be set to one 

with the exception of the least significant bit which shall be set to zero. If a 

SIM/USIM is inserted in a Mobile Equipment with the location area code containing 

all zeros, then the Mobile Equipment shall recognise this LAC as part of a deleted 

LAI 



10.5.1.4 



Mobile Identity 



The purpose of the Mobile Identity information element is to provide either the international mobile subscriber identity, 
IMSI, the temporary mobile subscriber identity, TMSI/P-TMSI/M-TMSI, the international mobile equipment identity, 
IMEI, the international mobile equipment identity together with the software version number, IMEISV, or the 
temporary mobile group identity (TMGI), associated with the optional MB MS Session Identity. 

The IMSI shall not exceed 15 digits, the TMSI/P-TMSI/M-TMSI is 4 octets long, and the IMEI is composed of 15 
digits, the IMEISV is 16 digits (see 3GPP TS 23.003 [10]). The TMGI is at maximum 6 octets long and is defined in 
subclause 10.5.6.13. The MBMS Session Identity, if included, is 1 octet long (see 3GPP TS 48.018 [86]). 
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For packet paging the network shall select the mobile identity type with the following priority: 

1- P-TMSI: The P-TMSI shall be used if it is available. 

2- IMSI: The IMSI shall be used in cases where no P-TMSI is available. 

For MBMS (pre-)notification (see 3GPP TS 44.018 [84] and 3GPP TS 44.060 [76]) the network shall select the mobile 
identity type "TMGI and optional MBMS Session Identity". 

NOTE 1: The type of identity "TMGI and optional MBMS Session Identity" is only used by the MBMS 
(pre-)notification procedure in of A/Gb mode. 

For all other transactions with the following exceptions: 

emergency call establishment, emergency call re-establishment, mobile terminated call establishment, the 
identification procedure, the GMM identification procedure, the GMM authentication, GPRS attach, routing area 
updating, and ciphering procedure and the ciphering mode setting procedure; and 

- location updating when the MS is configured for " Attach WithlMSI" as specified in 3GPP TS 24.368 [135] or 
3GPP TS 3 1 . 1 02 [ 11 2] and the selected PLMN is neither the registered PLMN nor in the list of equivalent 
PLMNs; 

the mobile station and the network shall select the mobile identity type with the following priority: 

1- TMSI: The TMSI shall be used if it is available. 

2- IMSI: The IMSI shall be used in cases where no TMSI is available. 

For mobile terminated call establishment the mobile station shall select the same mobile identity type as received from 
the network in the PAGING REQUEST message. In case of enhanced DTM CS estabhshment (see 3GPP TS 44.018 
[84]) the mobile station shall select the mobile identity type with the following priority in the PAGING RESPONSE 

message: 

1- TMSI: The TMSI shall be used if it is available. 

2- IMSI: The IMSI shall be used in cases where no TMSI is available. 

For the PAGING RESPONSE message sent as a response to a paging for CS fallback, the MS shall: 
select the TMSI as mobile identity type if the network has, in E-UTRAN, 

- paged the MS for CS fallback using the S-TMSI; or 

- indicated TMSI in the CS SERVICE NOTIFICATION message (see 3GPP TS 24.301 [120]); 
select the IMSI as mobile identity type if the network has, in E-UTRAN, 

- paged the MS for CS fallback using the IMSI; or 

- indicated IMSI in the CS SERVICE NOTIFICATION message (see 3GPP TS 24.301 [120]). 

For emergency call establishment and re-establishment the mobile station shall select the mobile identity type with the 
following priority: 

1- TMSI: The TMSI shall be used if it is available and if the location update status is UPDATED, and the stored 
LAI is equal to the one received on the BCCH from the current serving cell. 

2- IMSI: The IMSI shall be used in cases where no TMSI is available or TMSI is available but either the update 
status is different from UPDATED, or the stored LAI is different from the one received on the BCCH from 
the current serving cell. 

3- IMEI: The IMEI shall be used in cases where no SIM/USIM is available or the SIM/USIM is considered as 
not valid by the mobile station or no IMSI or TMSI is available. 

In the identification procedure and in the GMM identification procedure the mobile station shall select the mobile 
identity type which was requested by the network, if available. If the requested identity is not available, then the mobile 
station shall indicate the identity type "No Identity". 
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In the ciphering mode setting procedure and in the GMM authentication and ciphering procedure the mobile shall select 
the IMEISV. 

The Mobile Identity information element is coded as shown in figure 10.5.4/3GPP TS 24.008 and table 10.5.4/3GPP TS 
24.008. 

The Mobile Identity is a type 4 information element with a minimum length of 3 octet and 1 1 octets length maximal. 
Further restriction on the length may be applied, e.g. number plans. 



8 7 6 5 


4 


3 2 1 


1 IVIobile Identity lEI 


Length of mobile identity contents 


Identity digit 1 


odd/ 
even 
indie 


Type of identity 


Identity digit p+1 


Identity digit p 



oetet 1 
oetet 2 
oetet 3 

oetet 4* 
Figure 10.5.4/3GPP TS 24.008 Mobile /denf/fy information element 



IVIobile Identity lEI 


octet 1 


Length of Mobile Identity contents 


octet 2 



spare 


MBMS 

Sess 

Id indie 


MCC/ 
MNC 
indie 


odd/ 
even 
indie 


Type of identity 


octet 3 


MBMS Service ID 


octet 4 
octet 5 
octet 6 


MCC digit 2 


MCC digit 1 


octet 6a* 


MNCdigitS 


MCC digit 3 


octet 6b* 


MNCdigit2 


MNC digit 1 


octet 6c* 


MBMS Session Identity 


octet 7* 



Figure 10.5.4a/3GPP TS 24.008: Mobile /denf/fy information element for type of identity "TMGI and 

optional MBMS Session Identity" 
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Table 10.5.4/3GPP TS 24.008: Mobile /c/enWy information element 



Type of identity (octet 3) 


Bits 






3 


2 


1 










1 


IMSI 





1 





IMEI 





1 


1 


IMEISV 


1 








TMSI/P-TMSI/M-TMSI 


1 





1 


TIVIGl and optional IVIBIVIS Session Identity 











No Identity (note 1) 



All other values are reserved. 

Odd/even indication (octet 3) 

Bit 

4 

even number of identity digits and also when the TMSI/P-TMSI or TIVIGl 
and optional MBMS Session Identity is used 

1 odd number of identity digits 

Identity digits (octet 3 etc) 

For the IIVISI, IMEI and IMEISV this field is coded using BCD coding. If the number 
of identity digits is even then bits 5 to 8 of the last octet shall be filled with an end 
mark coded as "1111". 

For Type of identity "No Identity", the Identity digit bits shall be encoded with all Os 
and the Length of mobile identity contents parameter shall be set to one of the 
following values: 

- "1" if the identification procedure is used (see subclause 9.2.1 1); 

- "3" if the GMM identification procedure is used (see subclause 9.4.13) 

- "3" if the EMM identification procedure is used (see 3GPP TS 24.301 [120]) 

If the mobile identity is the TMSI/P-TMSI/M-TMSI then bits 5 to 8 of octet 3 are 
coded as "1 111" and bit 8 of octet4 is the most significant bit and bit 1 of the last 
octet the least significant bit. The coding of the TMSI/P-TMSI is left open for each 
administration. 

For type of identity "TMGI and optional MBMS Session Identity" the coding of octet 
3 etc is as follows: 

MCC/MNC indication (octet 3) 

Bit 

5 

MCC/MNC is not present 

1 MCC/MNC is present 

MBMS Session Identity indication (octet 3) 

Bit 

6 

MBMS Session Identity is not present 

1 MBMS Session Identity is present 
MBMS Service ID (octet 4, 5 and 6) 

The contents of the MBMS Service ID field are coded as octets 3 to 5 of the 
Temporary Mobile Group Identity IE in Figure 10.5.154/3GPP TS 24.008. 
Therefore, bit 8 of octet 4 is the most significant bit and bit 1 of octet 6 the least 
significant bit. The coding of the MBMS Service ID is the responsibility of each 
administration. Coding using full hexadecimal representation may be used. The 
MBMS Service ID consists of 3 octets. 

MCC, Mobile country code (octet 6a, octet 6b bits 1 to 4) 

The MCC field is coded as in ITU-T Rec. E.212, Annex A. 
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MNC, Mobile network code (octet 6b bits 5 to 8, octet 6c) 

The coding of this field is the responsibility of each administration but BCD coding 
shall be used. The MNC shall consist of 2 or 3 digits. If a network operator decides 
to use only two digits in the IVINC, bits 5 to 8 of octet 6b shall be coded as "1 111". 

The contents of the MCC and IVINC digits are coded as octets 6 to 8 of the 
Temporary Mobile Group Identity IE in Figure 10.5.154/3GPP TS 24.008. 

MBMS Session Identity (octet 7) 

The MBMS Session Identity field is encoded as the value part of the MBMS 
Session Identity IE as specified in 3GPP TS 48.018 [86]. 



NOTE 1 : This can be used in the case when a fill paging message without any 
valid identity has to be sent on the paging subchannel and when the 
requested identity is not available at the mobile station during the identity 

request procedure. 



10.5.1.5 



Mobile Station Classmark 1 



The purpose of the Mobile Station Classmark 1 information element is to provide the network with information 
concerning aspects of high priority of the mobile station equipment. This affects the manner in which the network 
handles the operation of the mobile station. The Mobile Station Classmark information indicates general mobile station 
characteristics and it shall therefore, except for fields explicitly indicated, be independent of the frequency band of the 
channel it is sent on. 

The Mobile Station Classmark 1 information element is coded as shown in figure 10.5.5/3GPP TS 24.008 and 
table 10.5.5/3GPP TS 24.008. 

The Mobile Station Classmark 7 is a type 3 information element with 2 octets length. 



8 


7 6 


5 


4 


3 2 1 




Mobile Station Classmark 1 lEI 



spare 


Revision 
level 


ES 
IND 


A5/1 


RF power 
capability 



octet 1 
octet 2 
Figure 10.5.5/3GPP TS 24.008 Mobile Station Classmark 1 information element 
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Table 10.5.5/3GPP TS 24.008: Mobile Station Ciassmarii 1 information element 



Revision level (octet 2) 
Bits 



Reserved for GSIVI phase 1 

Used by GSM phase 2 mobile stations 

Used by mobile stations supporting R99 or later versions of the protocol 

Reserved for future use. If the network receives a revision level specified as 

'reserved for future use', then it shall use the highest revision level supported 

by the network. 



ES IND (octet 2, bit 5) "Controlled Early Classmark Sending" option implementation 

An MS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

"Controlled Early Classmark Sending" option is not implemented in the MS 

1 "Controlled Early Classmark Sending" option is implemented in the MS 

NOTE 1 : The value of the ES IND gives the Implementation in the MS. It's value is not 
dependent on the broadcast SI 3 Rest Octet <Early Classmark Sending 
Controb value. 

A5/1 algorithm supported (octet 2, bit4) (Note 2) 

An MS not supporting A/Gb mode shall set this bit to '1 '. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

encryption algorithm A5/1 available 

1 encryption algorithm A5/1 not available 

RF power capability (octet 2) 

When GSM 450, GSM 480, GSM 710, GSM 750, T-GSM 810, GSM 850, GSM 900 P, E 

[or R] band is used (for exceptions see 3GPP TS 44.018 [84]), the MS shall indicate the 

RF power capability of the band used (see table): 

When UMTS is used, a single band GSM 450, GSM 480, GSM 710, GSM 750, T-GSM 

810, GSM 850, GSM 900 P, E [or R] MS shall indicate the RF power capability 

corresponding to the (GSM) band it supports (see table). In this case information on 

which single band Is supported is found in classmark 3. 

Bits 



3 


2 


1 













class 1 








1 


class 2 





1 





class 3 





1 


1 


class 4 


1 








class 5 



All other values are reserved. 

When the GSM 1800 or GSM 1900 band Is used (for exceptions see 3GPP TS 44.018 
[84], sub-clause 3.4.18), the MS shall Indicate the RF power capability of the band used 
(see table): 

When UMTS is used, a single band GSM 1800 or GSM 1900 MS shall indicate the RF 
power capability corresponding to the (GSM) band it supports (see table). In this case, 
information on which single band is supported is found in classmark 3. 
Bits 
! 1 

class 1 

class 2 

class 3 

All other values are reserved. 

When UMTS is used, an MS not supporting any GSM band or a multiband GSM MS 
shall code this field as follows (see table): 
Bits 

3 2 1 

1 1 1 RF power capability Is irrelevant in this information element. 
All other values are reserved. 



3 


2 


1 

















1 





1 
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NOTE 2: The requirements for the support of the A5 algorithms in the IVIS are specified 
in 3GPPTS 43.020 [13], 



10.5.1.6 



Mobile Station Classmark 2 



The purpose of the Mobile Station Classmark 2 information element is to provide the network with information 
concerning aspects of both high and low priority of the mobile station equipment. This affects the manner in which the 
network handles the operation of the mobile station. The Mobile Station Classmark information indicates general 
mobile station characteristics and it shall therefore, except for fields explicitly indicated, be independent of the 
frequency band of the channel it is sent on. 

The Mobile Station Classmark 2 information element is coded as shown in figure 10.5.6/3GPP TS 24.008, 
table 10.5.6a/3GPP TS 24.008 and table 10.5.6b/3GPP TS 24.008. 

The Mobile Station Classmark 2 is a type 4 information element with 5 octets length. 



8 


7 


6 


5 


4 


3 


2 


1 


IVIobile station classmarl< 2 lEI 


Length of mobile station classmark 2 contents 



spare 


Revision 
level 


ES 
IND 


A5/1 


RF power 
capability 



spare 


PS 
capa. 


SS Screen. 
Indicator 


SIVIca 
pabi. 


VBS 


VGCS 


PC 


CM3 



spare 


LCSVA 
CAP 


UCS2 


SoLSA 


CMSP 


A5/3 


A5/2 



octet 1 

octet 2 

octet 3 

octet 4 

octet 5 

NOTE 1 : Owing to backward compatibility problems, bit 8 of octet 4 should not be used unless it is also checked 
that the bits 8, 7 and 6 of octet 3 are not "0 0". 

Figure 10.5.6/3GPP TS 24.008 Mobile Station C/ass/narfc 2 information element 



Table 10.5.6a/3GPP TS 24.008: iVIobiie Station C/ass/nar^ 2 information element 



Revision level (octet 3) 
Bits 
7 6 


1 

1 

1 1 



Reserved for GSIVI phase 1 

Used by GSM phase 2 mobile stations 

Used by mobile stations supporting R99 or later versions of the protocol 

Reserved for future use. If the network receives a revision level specified as 'reserved 

for future use', then it shall use the highest revision level supported by the network. 



ES IND (octet 3, bit 5) "Controlled Early Classmark Sending" option implementation 

AN MS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

"Controlled Early Classmark Sending" option is not implemented In the MS 

1 "Controlled Early Classmark Sending" option is implemented in the MS 

NOTE 1 : The value of the ES IND gives the implementation in the MS. It's value is not 

dependent on the broadcast SI 3 Rest Octet <Early Classmark Sending Control> value 
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Table 10.5.6a/3GPP TS 24.008: Mobile Station C/assmarfc 2 information element 



A5/1 algorithm supported (octet 3, bit 4) (Note 4) 

An IVIS not supporting A/Gb mode shall set this bit to '1 '. 

An MS supporting A/Gb mode shall indicate the associated capability (see table) 

encryption algorithm A5/1 available 

1 encryption algorithm A5/1 not available 

RF Power Capability (Octet 3) 

When T-GSM 380, T-GSM 410, GSM 450, GSM 480, GSM 710, GSM 750, T-GSM 810, GSM 

850, GSM 900 P, E [or R] band is used (for exceptions see 3GPP TS 44.018 [84]), the MS shall 

indicate the RF power capability of the band used (see table). 

When UMTS or E-UTRAN is used, a single band T-GSM 380, T-GSM 410, GSM 450, GSM 480, 



GSM 710, GSM 750, T-GSM 810, GSM 850, GSM 900 
capability corresponding to the (GSM) band it supports 
which single band is supported is found in classmark 3. 
Bits 



P, E [or R] MS shall indicate the RF power 
(see table). In this case, information on 



3 


2 


1 













class 1 








1 


class 2 





1 





class 3 





1 


1 


class 4 


1 








class 5 



All other values are reserved. 

When the GSM 1800 or GSM 1900 band is used (for exceptions see 3GPP TS 44.018 [84]) The 

MS shall indicate the RF power capability of the band used (see table). 

When UMTS or E-UTRAN is used, a single band GSM 1800 or GSM 1900 MS shall indicate the 

RF power capability corresponding to the (GSM) band it supports (see table). In this case, 

information on which single band is supported is found in classmark 3 

Bits 



3 2 





1 



class 1 
class 2 
class 3 



All other values are reserved. 

When UMTS or E-UTRAN is used, an MS not supporting any GSM band or a multiband GSM MS 

shall code this field as follows (see table): 

Bits 

3 2 1 

1 1 1 RF Power capability is irrelevant in this information element 

All other values are reserved. 

PS capability (pseudo-synchronization capability) (octet 4) 

An MS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

Bit? 

PS capability not present 

1 PS capability present 

SS Screening Indicator (octet 4) 
Bits 



defined in 3GPP TS 24.080 [24] 
defined in 3GPP TS 24.080 [24] 
defined in 3GPP TS 24.080 [24] 
defined in 3GPP TS 24.080 [24] 



SM capability (MT SMS pt to pt capability) (octet 4) 
Bit 4 

Mobile station does not support mobile terminated point to point SMS 

1 Mobile station supports mobile terminated point to point SMS 



6 


5 











1 


1 





1 


1 
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Table 10.5.6a/3GPP TS 24.008: Mobile Station C/assmarfc 2 information element 



VBS notification reception (octet 4) 

An IVIS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

Bits 

no VBS capability or no notifications wanted 

1 VBS capability and notifications wanted 

VGGS notification reception (octet 4) 

An MS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

Bit 2 

no VGGS capability or no notifications wanted 

1 VGGS capability and notifications wanted 

FC Frequency Capability (octet 4) 

When the T-GSM 400, GSM 400, or GSM 700, or T-GSM 81 0, or GSM 850, or GSM 1 800, or 
GSM 1900 band or UMTS or E-UTRAN is used (for exceptions see 3GPP TS 44.018 [84]), for 
definitions of frequency band see 3GPP TS 45.005 [33]), this bit shall be sent with the value '0'. 

NOTE 2: This bit conveys no information about support or non support of the E-GSM or R-GSM 
bands when T-GSM 400, GSM 400, GSM 700, T-GSM 810, GSM 850, GSM 1800, GSM 1900 
band or UMTS or E-UTRAN is used. 

When a GSM 900 band is used (for exceptions see 3GPP TS 44.018 [84]): 
Biti 

The MS does not support the E-GSM or R-GSM band (For definition of frequency 
bands see 3GPP TS 45.005 [33]) 

1 The MS does support the E-GSM or R-GSM (For definition of frequency bands see 
3GPP TS 45.005 [33]) 

NOTE 3: For mobile station supporting the R-GSM band further information can be found in MS 
Glassmark 3. 

CM3 (octet 5, bit 8) 

The MS does not support any options that are indicated in CM3 

1 The MS supports options that are indicated in classmark 3 IE 

LCS VA capability (LCS value added location request notification capability) (octet 5, bit 6) 

This information field indicates the support of the LCS value added location request notification via 
CS domain as defined in 3GPP TS 23.271 [105]. 

location request notification via CS domain not supported 

1 location request notification via CS domain supported 

UCS2 treatment (octet 5, bit 5) 

This information field indicates the likely treatment by the mobile station of UCS2 encoded 
character strings. For backward compatibility reasons, if this field is not included, the value shall 
be assumed by the receiver. 

the ME has a preference for the default alphabet (defined in 3GPP TS 23.038 [8b]) 
over UCS2. 

1 the ME has no preference between the use of the default alphabet and the use of 
UCS2. 
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Table 10.5.6a/3GPP TS 24.008: Mobile Station C/assmarfc 2 information element 



SoLSA (octet 5, bit 4) 

An MS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

The ME does not support SoLSA. 

1 The ME supports SoLSA. 

OMSP: CM Service Prompt (octet 5, bit 3) $(GGBS)$ 

"Network initiated MO GM connection request" not supported. 

1 "Network initiated MO GM connection request" supported for at least one GM protocol. 

A5/3 algorithm supported (octet 5, bit 2) (Note 4) 

An MS not supporting A/Gb mode shall set this bit to '0'. 

An MS supporting A/Gb mode shall indicate the associated capability (see table): 

encryption algorithm A5/3 not available 

1 encryption algorithm A5/3 available 

A5/2 algorithm supported (octet 5, bit 1) (Note 4) 

The MS shall set this bit to '0'. 

The network shall accept any received value. 

encryption algorithm A5/2 not available 

1 Not used. This value was allocated in earlier versions of the protocol. 



NOTE 4: The requirements for the support of the A5 algorithms in the MS are specified in 
3GPPTS 43.020 [13]. 



NOTE 2: Additional mobile station capability information might be obtained by invoking the classmark 
interrogation procedure when GSM is used. 



10.5.1.7 



Mobile Station Classmark 3 



The purpose of the Mobile Station Classmark 3 information element is to provide the network with information 
concerning aspects of the mobile station. The contents might affect the manner in which the network handles the 
operation of the mobile station. The Mobile Station Classmark information indicates general mobile station 
characteristics and it shall therefore, except for fields explicitly indicated, be independent of the frequency band of the 
channel it is sent on. 

The Mobile Station Classmark 5 is a type 4 information element with a maximum of 34 octets length. 

The value part of a Mobile Station Classmark 3 information element is coded as shown in figure 10.5.7/3GPP TS 
24.008 and table 10.5.7/3GPP TS 24.008. 

NOTE: The 34 octet limit is so that the CLASSMARK CHANGE message will fit in up to two layer 2 frames. 

SEMANTIC RULE: a multiband mobile station shall provide information about all frequency bands it can support. A 
single band mobile station shall not indicate the band it supports in the Multiband Supported, GSM 400 Bands 
Supported, GSM 710 Associated Radio Capability, GSM 750 Associated Radio Capability, T-GSM 810 Associated 
Radio Capability, GSM 850 Associated Radio Capability or GSM 1 900 Associated Radio Capability fields in the 
Mobile Station Classmark 3. Due to shared radio frequency channel numbers between GSM 1800 and GSM 1900, the 
mobile should indicate support for either GSM 1800 band OR GSM 1900 band. 

SEMANTIC RULE: a mobile station shall include the MS Measurement Capability field if the Multi Slot Class field 
contains a value of 19 or greater (see 3GPP TS 45.002 [32]). 

Typically, the number of spare bits at the end is the minimum to reach an octet boundary. The receiver may add any 
number of bits set to "0" at the end of the received string if needed for correct decoding. 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 10 41 ETSI TS 1 24 008 VI 0.1 0.0 (201 3-04) 



<Classmark 3 Value part> ::= 

< spare bit > 

{ < Multiband supported : { 000 } > 

< A5 bits > 

I < IVIultiband supported :{ 101 I 110} > 

< A5 bits > 

< Associated Radio Capability 2 : bit(4) > 

< Associated Radio Capability 1 : bit{4) > 
I < IVIultiband supported : { 001 | 010 | 100 } > 

< A5 bits > 

< spare bit >(4) 

< Associated Radio Capability 1 : bit(4) > } 
{ I 1 < R Support > } 

{ I 1 < HSCSD IVIuIti Slot Capability > } 

< UCS2 treatment: bit > 

< Extended IVIeasurement Capability : bit > 
{ I 1 < MS measurement capability > } 

{ I 1 < IVIS Positioning IVIethod Capability > } 

{ I 1 < ECSD IVIuIti Slot Capability > } 

{ I 1 < 8-PSK Struct > } 

{ I 1 < GSM 400 Bands Supported : { 01 | 10 | 11 } > 

< GSM 400 Associated Radio Capability: bit(4) > } 

{ I 1 <GSM 850 Associated Radio Capability : bit{4) > } 
{ I 1 <GSM 1900 Associated Radio Capability : bit(4) > } 

< UMTS FDD Radio Access Technology Capability : bit > 

< UMTS 3.84 Mcps TDD Radio Access Technology Capability : bit > 

< CDMA 2000 Radio Access Technology Capability : bit > 

{ I 1 < DTM GPRS Multi Slot Class : bit(2) > 

< Single Slot DTM : bit > 

{0 I 1< DTM EGPRS Multi Slot Class : bit(2) > } } 
{ I 1 < Single Band Support > } -- Release 4 starts here: 

{ I 1 <GSM 750 Associated Radio Capability : bit{4)>} 

< UMTS 1 .28 Mcps TDD Radio Access Technology Capability : bit > 

< GERAN Feature Package 1 : bit > 

{ I 1 < Extended DTM GPRS Multi Slot Class : bit(2) > 

< Extended DTM EGPRS Multi Slot Class : bit{2) > } 

{ I 1 < High Multislot Capability : bit(2) > } -Release 5 starts here. 

{ I 1 < GERAN lu Mode Capabilities > } 

< GERAN Feature Package 2 : bit > 

< GMSK Multislot Power Profile : bit (2) > 

< 8-PSK Multislot Power Profile : bit (2) > 

{ I 1 < T-GSM 400 Bands Supported : { 01 | 1 | 1 1 } > - Release 6 starts here. 

< T-GSM 400 Associated Radio Capability: bit{4) > } 

~ The value '1 ' was allocated in an earlier version of the protocol and shall not be used. 

< Downlink Advanced Receiver Performance : bit {2)> 

< DTM Enhancements Capability : bit > 

{ I 1 < DTM GPRS High Multi Slot Class : bit(3) > 

< Offset required : bit> 

{ I 1 < DTM EGPRS High Multi Slot Class : bit{3) > } } 

< Repeated ACCH Capability : bit > 

{ I 1 <GSM 710 Associated Radio Capability : bit(4)>} - Release 7 starts here. 

{ I 1 <T-GSM 810 Associated Radio Capability : bit(4)>} 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 411 ETSI TS 124 008 V10.10.0 (2013-04) 



< Ciphering Mode Setting Capability : bit > 

< Additional Positioning Capabilities : bit > 

< E-UTRA FDD support : bit > -- Release 8 starts here 

< E-UTRA TDD support : bit > 

< E-UTRA Measurement and Reporting support : bit > 

< Priority-based reselection support : bit > 

< UTRA CSG Cells Reporting : bit > - Release 9 starts here 

< VAMOS Level : bit{2) > 

< TIGHTER Capability : bit(2) > - Release 10 starts here 

< Selective Ciphering of Downlink SACCH : bit > 

< spare bits > ; 

< A5 bits > ::= 

< A5/7 : bit >< A5/6 : bit >< A5/5 : bit >< ASM : bit > ; 

<R Support>::= 

< R-GSM band Associated Radio Capability : bit(3) > ; 

< HSCSD Multi Slot Capability > ::= 

< HSCSD Multi Slot Class : bit{5) > ; 

< MS Measurement capability > ;:= 

< SMS_VALUE : bit (4) > 

< SM_VALUE : bit (4) > ; 

< MS Positioning Method Capability > ::= 

< MS Positioning Method : bit(5) > ; 

< ECSD Multi Slot Capability > ::= 

< ECSD Multi Slot Class : bit(5) > ; 

< 8-PSK Struct> : := 

< Modulation Capability : bit > 

{ I 1 < 8-PSK RF Power Capability 1 : bit(2) > } 
{ I 1 < 8-PSK RF Power Capability 2: bit(2) > } 

< Single Band Support > ::= 

< GSM Band : bit (4) > ; 

< GERAN lu Mode Capabilities > ::= 

< Length : bit (4) > - length in bits of lu mode only capabilities and spare bits 
- Additions in release 6 

< FLO lu Capability : bit > 

<spare bits>** ; - expands to the indicated length 

— may be used for future enhancements 



Figure 10.5.7/3GPP TS 24.008 Mobile Station Ciassmarfi 3 information element 
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Table 10.5.7/3GPP TS 24.008: Mobile Station Ciassmaric 3 information element 



Multiband Supported (3 bit field) 

Band 1 supported 
Bit 1 

P-GSM not supported 

1 P-GSM supported 

Band 2 supported 
Bit 2 

E-GSM or R-GSM not supported 

1 E-GSM or R-GSM supported 

Band 3 supported 
Bit 3 

GSM 1 800 not supported 

1 GSM 1800 supported 

The indication of support of P-GSM band or E-GSM or R-GSM band is mutually exclusive. 

When the 'Band 2 supported' bit indicates support of E-GSM or R-GSM, the presence of the <R Support> field, 
see below, indicates if the E-GSM or R-GSM band is supported. 

In this version of the protocol, the sender indicates in this field either none, one or two of these 3 bands 
supported. 

For single band mobile station or a mobile station supporting none of the GSM 900 bands(P-GSM, E-GSM and 
R-GSM) and GSM 1 800 bands, all bits are set to 0. 

A5/4 

Encryption algorithm A5/4 not available 

1 Encryption algorithm A5/4 available 

A5/5 

Encryption algorithm A5/5 not available 

1 Encryption algorithm A5/5 available 

A5/6 

Encryption algorithm A5/8 not available 

1 Encryption algorithm A5/6 available 

A5/7 

Encryption algorithm A5/7 not available 

1 Encryption algorithm A5/7 available 

Associated Radio capability 1 and 2 (4 bit fields) 

If either of P-GSM or E-GSM or R-GSM is supported, the radio capability 1 field indicates the radio capability for 
P-GSM, E-GSM or R-GSM, and the radio capability 2 field indicates the radio capability for GSM 1800 if 
supported, and is spare otherwise. 

If none of P-GSM or E-GSM or R-GSM are supported, the radio capability 1 field indicates the radio capability 
for GSM 1800, and the radio capability 2 field is spare. 

The radio capability contains the binary coding of the power class associated with the band indicated in 
multiband support bits (see 3GPP TS 45.005 [33]). 



(continued...) 
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Table 10.5.1 .7/3GPP TS 24.008 (continued): Mobile Station Ciassmark 3 information element 



R-GSM band Associated Radio Capability (3 bit field) 

In case where the R-GSM band is supported the R-GSIVI band associated radio capability field contains the 
binary coding of the power class associated (see 3GPP TS 45.005 [33]) (regardless of the number of GSM 
bands supported). A mobile station supporting the R-GSM band shall also when appropriate, (see 10.5.1.6) 
indicate its support in the 'FG' bit in the Mobile Station Ciassmark 2 information element. 

NOTE: The coding of the power class for P-GSM, E-GSM, R-GSM and GSM 1 800 in radio capability 1 and/or 2 
is different to that used in the Mobile Station Ciassmark 1 and Mobile Station Ciassmark 2 information elements. 

HSCSD Multi Slot Class (5 bit field) 

In case the MS supports the use of multiple timeslots for HSCSD then the HSCSD Multi Slot Class field is coded 
as the binary representation of the multislot class defined in 3GPP TS 45.002 [32]. 

UCS2 treatment (1 bit field) 

This information field indicates the likely treatment by the mobile station of UCS2 encoded character strings. If 
not included, the value shall be assumed by the receiver. 

the ME has a preference for the default alphabet (defined in 3GPP TS 23.038 [8b]) over UCS2. 

1 the ME has no preference between the use of the default alphabet and the use of UCS2. 

Extended Measurement Capability (1 bit field) 

This bit indicates whether the mobile station supports 'Extended Measurements' or not 

the MS does not support Extended Measurements 

1 the MS supports Extended Measurements 

SMS_VALUE (Switch-Measure-Switch) (4 bit field) 

The SMS field indicates the time needed for the mobile station to switch from one radio channel to another, 

perform a neighbour cell power measurement, and the switch from that radio channel to another radio channel. 

Bits 

4321 

1/4 timeslot (-144 microseconds) 

1 2/4 timeslot (-288 microseconds) 

10 3/4 timeslot (-433 microseconds) 

1111 16/4 timeslot (-2307 microseconds) 

SM_VALUE (Switch-Measure) (4 bit field) 

The SM field indicates the time needed for the mobile station to switch from one radio channel to another and 

perform a neighbour cell power measurement. 

Bits 

4321 

1/4 timeslot (-144 microseconds) 

1 2/4 timeslot (-288 microseconds) 

10 3/4 timeslot (-433 microseconds) 

1111 16/4 timeslot (-2307 microseconds) 

MS Positioning Method (5 bit field) 

This field indicates the Positioning Method(s) supported by the mobile station for the provision of location 

services (LCS) via the CS domain in A-mode. 

MS assisted E-OTD 



Bit 5 

MS assisted E-OTD not supported 

1 MS assisted E-OTD supported 
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Table 10.5.1 .7/3GPP TS 24.008 (continued): Mobile Station Ciassmark 3 information element 



MS based E-OTD 



Bit 4 

MS based E-OTD not supported 

1 MS based E-OTD supported 

MS assisted GPS 



Bits 



MS assisted GPS not supported 

1 MS assisted GPS supported 

MS based GPS 
Bit 2 



MS based GPS not supported 

1 MS based GPS supported 

MS Conventional GPS 



Bit1 



conventional GPS not supported 

1 conventional GPS supported 

ECSD Multi Slot class (5 bit field) 

An MS that supports ECSD shall include this field to indicate its ECSD capability. Whether the MS is capable of 
8-PSK modulation in uplinl< is indicated by the value of the Modulation Capability field in the 8-PSK struct. The 
ECSD Multi Slot Class field is coded as the binary representation of the multislot class defined in 3GPP TS 
45.002 [32]. 

8-PSK struct 

The MS shall include the 8-PSK struct if it supports ECSD or DTM EGPRS or both. 
Modulation Capability 

The Modulation Capability field indicates the modulation scheme the MS supports in addition to GMSK. 

8-PSK supported for downlinl< reception only 

1 8-PSK supported for uplinl< transmission and downlink reception 

8-PSK RF Power Capability 1 (2 bit field) 

If 8-PSK modulation is supported for both uplink and downlink, the 8-PSK RF Power Capability 1 field indicates 
the radio capability for 8-PSK modulation in GSM 400, GSM 700, GSM 850 or GSM 900. 

8-PSK RF Power Capability 2 (2 bit field) 

If 8-PSK modulation is supported for both uplink and downlink, the 8-PSK RF Power Capability 2 field indicates 
the radio capability for 8-PSK modulation in GSM 1800 or GSM 1900 if supported, and is not included 
otherwise. 

The respective 8-PSK RF Power Capability 1 and 8-PSK RF Power Capability 2 fields contain the following 
coding of the 8-PSK modulation power class (see 3GPP TS 45.005 [33]): 
Bits 2 1 

Reserved 

1 Power class El 

1 Power class E2 
1 1 Power class E3 
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Table 10.5.1 .7/3GPP TS 24.008 (continued): Mobile Station Ciassmark 3 information element 



GSM 400 Bands Supported (2 bit field) 

See the semantic rule for the sending of this field. 
Bits 
21 

1 GSM 480 supported, GSM 450 not supported 

1 GSM 450 supported, GSM 480 not supported 
1 1 GSM 450 supported, GSM 480 supported 

GSM 400 Associated Radio Capability (4 bit field) 

If either GSM 450 or GSM 480 or both is supported, the GSM 400 Associated Radio Capability field indicates 
the radio capability for GSM 450 and/or GSM 480. 

The radio capability contains the binary coding of the power class associated with the band indicated in GSM 
400 Bands Supported bits (see 3GPP TS 45.005 [33]). 

NOTE: The coding of the power class for GSM 450 and GSM 480 in GSM 400 Associated Radio Capability is 
different to that used in the Mobile Station Ciassmark 1 and Mobile Station Ciassmark 2 information elements. 

GSM 850 Associated Radio Capability (4 bit field) 

See the semantic rule for the sending of this field. 

This field indicates whether GSM 850 band is supported and its associated radio capability. 

The radio capability contains the binary coding of the power class associated with the GSM 850 band (see 
3GPP TS 45.005 [33]). 

Note: the coding of the power class for GSM 850 in GSM 850 Associated Radio Capability is different to that 
used in the Mobile Station Ciassmark 1 and Mobile Station Ciassmark 2 information elements. 

GSM 1900 Associated Radio Capability (4 bit field) 

See the semantic rule for the sending of this field. 

This field indicates whether GSM 1 900 band is supported and its associated radio capability. 

The radio capability contains the binary coding of the power class associated with the GSM 1900 band (see 
3GPP TS 45.005 [33]). 

Note: the coding of the power class for GSM 1900 in GSM 1900 Associated Radio Capability is different to that 
used in the Mobile Station Ciassmark 1 and Mobile Station Ciassmark 2 information elements. 
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Table 10.5.1 .7/3GPP TS 24.008 (continued): Mobile Station Ciassmark 3 information element 



UMTS FDD Radio Access Technology Capability (1 bit field) 

UMTS FDD not supported 

1 UMTS FDD supported 

UMTS 3.84 Mcps TDD Radio Access Technology Capability (1 bit field) 

UMTS 3.84 Mcps TDD not supported 

1 UMTS 3.84 Mcps TDD supported 

CDMA 2000 Radio Access Technology Capability (1 bit field) 

CDMA2000 not supported 

1 CDMA2000 supported 

DTM GPRS Multi Slot Class (2 bit field) 

This field indicates the DTM GPRS multislot capabilities of the MS. It is coded as follows: 

Bit 

21 

Unused. If received, the network shall interpret this as '01 ' 

1 Multislot class 5 supported 

1 Multislot class 9 supported 

1 1 Multislot class 1 1 supported 

If a multislot class type 1 MS indicates the support of a DTM GPRS multislot class for which three uplink 
timeslots can be assigned, the mobile station shall support Extended Dynamic Allocation. 

This field shall contain one of the following values if the DTM GPRS High Multi Slot Class field is present: 

- Multislot class 9 if DTM GPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41 ; 

- Multislot class 1 1 if DTM GPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or 

Classes 42, 43, 44. 

The same multislot capability is applicable also for EGPRS2 if supported. 

Single Slot DTM (1 bit field) 

This field indicates whether the MS supports single slot DTM operation (see 3GPP TS 43.055 [87]). It is coded 

as follows: 

Single Slot DTM not supported 

1 Single Slot DTM supported 

An MS indicating support for Extended DTM GPRS multislot class or Extended DTM EGPRS multislot class 
shall set this bit to '1 '. The network may ignore the bit in this case. 

DTM EGPRS Multi Slot Class (2 bit field) 

This field indicates the DTM EGPRS multislot capabilities of the MS. Whether the MS is capable of 8-PSK 
modulation in uplink is indicated by the value of the Modulation Capability field in the 8-PSK struct. This field 
shall be included only if the mobile station supports EGPRS DTM. This field is coded as the DTM GPRS Multi 
Slot Class field. 

If a multislot class type 1 MS indicates the support of a DTM EGPRS multislot class for which three uplink 
timeslots can be assigned, the mobile station shall support Extended Dynamic Allocation. 

This field shall contain one of the following values if the DTM EGPRS High Multi Slot Class field is present: 

- Multislot class 9 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41 ; 

- Multislot class 1 1 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or 

Classes 42, 43, 44. 

Single Band Support 

This field shall be sent if the mobile station supports UMTS and one and only one GSM band with the exception 
of R-GSM; this field shall not be sent otherwise 

GSM Band (4 bit field) 
Bits 

4321 

E-GSM is supported 

1 P-GSM is supported 
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10 GSM 1800 is supported 

11 GSM 450 is supported 

10 GSM 480 is supported 

10 1 GSM 850 is supported 

110 GSM 1900 is supported 

111 GSM 750 is supported 

10 GSM 71 is supported 

10 1 T-GSM 81 is supported 
All other values are reserved for future use. 

NOTE: When this field is received, the associated RF power capability is found in Classmark 1 or 2. 

GSM 750 Associated Radio Capability (4 bit field) 

See the semantic rule for the sending of this field. 

This field indicates whether GSM 750 band is supported and its associated radio capability. 

The radio capability contains the binary coding of the power class associated with the GSM 750 band (see 
3GPP TS 45.005 [33]). 

NOTE: The coding of the power class for GSM 750 in GSM 750 Associated Radio Capability is different to that 
used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements. 

UMTS 1.28 Mcps TDD Radio Access Technology Capability (1 bit field) 

UMTS 1 .28 Mcps TDD not supported 

1 UMTS 1 .28 Mcps TDD supported 

GERAN Feature Package 1 (1 bit field) 

This field indicates whether the MS supports the GERAN Feature Package 1 (see 3GPP TS 44.060 [76]). It is 

coded as follows: 

GERAN feature package 1 not supported. 

1 GERAN feature package 1 supported. 

Extended DTM GPRS Multi Slot Class (2 bit field) 

This field indicates the extended DTM GPRS multislot capabilities of the MS and shall be interpreted in 
conjunction with the DTM GPRS Multi Slot Class field. It is coded as follows, where 'DGMSC denotes the DTM 
GPRS Multi Slot Class field: 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Multislot class 5 supported 

Multislot class 6 supported 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Multislot class 9 supported 

Multislot class 1 supported 

Unused. If received, it shall be interpreted as '10 00' 

Unused. If received, it shall be interpreted as '10 00' 

Multislot class 1 1 supported 

Unused. If received, it shall be interpreted as '1 1 00' 

Unused. If received, it shall be interpreted as '1 1 00' 

Unused. If received, it shall be interpreted as '11 00' 

The presence of this field indicates that the MS supports combined fullrate and halfrate GPRS channels in the 
downlink.When this field is not present, the MS supports the multislot class indicated by the DTM GPRS Multi 
Slot Class field. 

If this field is included, it shall contain one of the following values if the DTM GPRS High Multi Slot Class field is 
present: 

- Multislot class 10 if DTM GPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41 ; 

- Multislot class 1 1 if DTM GPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or 

Classes 42, 43, 44. 

Extended DTM EGPRS Multi Slot Class (2 bit field) 
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This field is not considered when the DTIVI EGPRS IVIuIti Slot Class field is not included. This field indicates the 
extended DTIVI EGPRS multislot capabilities of the MS and shall be interpreted in conjunction with the DTIVI 
EGPRS Multi Slot Glass field. This field is coded as the Extended DTIVI GPRS Multi Slot Class field. The 
presence of this field indicates that the IVIS supports combined fullrate and halfrate GPRS channels in the 
downlink. When this field is not present, the MS supports the multislot class indicated by the DTM EGPRS Multi 
Slot Class field. 

If this field is included, it shall contain one of the following values if the DTM EGPRS High Multi Slot Class field 
is present: 

- Multislot class 10 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41 ; 

- Multislot class 1 1 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or 
Classes 42, 43, 44. 

High lUlultislot Capability (2 bit field) 

This field indicates the support of multislot classes 30 to 45, see 3GPP TS 45.002 [32]. 

The High Multislot Capability is individually combined with each multislot class field sent by the MS (the possible 

multislot class fields are: GPRS multislot class, EGPRS multislot class) to extend the related multislot class with 

the rule described in the MS Radio Access Capability IE. The same capability is applicable also to EGPRS2 if 

supported. 

GERAN lu Mode Capabilities 

This field indicates if the mobile station supports GERAN lu mode. Furthermore, it indicates the GERAN lu 
mode capabilities of the mobile station. The field shall be included if the mobile station supports GERAN lu 
mode. If the field is not present, the mobile station does not support GERAN lu mode. 

FLO lu Capability (1 bit field) 

If this parameter is not present, the value '0' shall be assumed by the receiver. 

FLO in GERAN lu mode not supported 

1 FLO in GERAN lu mode supported 

GERAN Feature Package 2 (1 bit field) 

This field indicates the MS support of the GERAN Feature Package 2. The GERAN Feature Package 2 includes 

Enhanced Power Control (ERG) (see 3GPP TS 45.008 [34]). 

GERAN feature package 2 not supported. 

1 GERAN feature package 2 supported. 

GMSK Multislot Power Profile (2 bit field) 

This field indicates the GMSK multislot power capability parameter GMSK_MULTISLOT_POWER_PROFILE as 

described in 3GPP TS 45.005 [33]. 

Bits 

21 

GMSK_MULTISLOT_POWER_PROFILE 

1 GMSK_MULTISLOT_POWER_PROFILE 1 

1 GMSK_MULTISLOT_POWER_PROFILE 2 
1 1 GMSK_MULTISLOT_POWER_PROFILE 3 

8-PSK Multislot Power Profile (2 bit field) 

This field indicates the 8-PSK multislot power capability parameter 8-PSK_MULTISL0T_P0WER_PR0FILE as 

described in 3GPP TS 45.005 [33]. If the MS does not support 8-PSK in the uplink, then it shall set this field to '0 

0'. 

Bits 

21 

8-PSK_MULTISL0T_P0WER_PR0FILE 

1 8-PSK_MULTISL0T_P0WER_PR0FILE 1 

1 8-PSK_MULTISL0T_P0WER_PR0FILE 2 
1 1 8-PSK_MULTISL0T_P0WER_PR0FILE 3 

T-GSM 400 Bands Supported (2 bit field) 

See the semantic rule for the sending of this field. 
Bits 
21 

1 T-GSM 380 supported, T-GSM 41 not supported 

1 T-GSM 410 supported, T-GSM 380 not supported 

1 1 T-GSM 410 supported, T-GSM 380 supported 
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T-GSM 400 Associated Radio Capability (4 bit field) 

If either T-GSM 41 or T-GSM 380 or both is supported, the T-GSM 400 Associated Radio Capability field 
indicates the radio capability for T-GSM 41 and/or T-GSM 380. 

The radio capability contains the binary coding of the power class associated with the band indicated in T-GSM 
400 Bands Supported bits (see 3GPP TS 45.005 [33]). 

NOTE: The coding of the power class for T-GSM 41 and T-GSM 380 in T-GSM 400 Associated Radio 
Capability is different to that used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information 
elements. 

Downlink Advanced Receiver Performance (2 bit field) 

This field indicates Downlink Advanced Receiver Performance capabilities of the MS (see 3GPP TS 45.005 

[33]). 

Bits 

21 

Downlink Advanced Receiver Performance not supported 

1 Downlink Advanced Receiver Performance - phase I supported 

1 Downlink Advanced Receiver Performance - phase II supported 

The value '1 1 ' shall not be used by the MS. 

If the value '1 1 ' is received by the network, it shall be interpreted as '10'. 

DIM Enhancements Capability (1 bit field) 

This field indicates whether the mobile station supports enhanced DTM CS establishment and enhanced DTM 

CS release or not. It is coded as follows: 

The mobile station does not support enhanced DTM CS establishment and enhanced DTM CS release 
procedures. 

1 The mobile station supports enhanced DTM CS establishment and enhanced DTM CS release 
procedures. 

DTM GPRS High Multi Slot Class (3 bit field) 

This field indicates the DTM GPRS multislot capabilities of the MS. It is coded as follows: 

Bit 

321 

Unused. If received, the network shall interpret this as '0 1 ' 

1 Multislot class 31 or 36 supported 

1 Multislot class 32 or 37 supported 

1 1 Multislot class 33 or 38 supported 

1 Multislot class 41 supported 
1 1 Multislot class 42 supported 
1 1 Multislot class 43 supported 
1 1 1 Multislot class 44 supported 

The presence of this field indicates that the MS supports the DTM extension to high multislot classes. When this 
field is not present, the MS supports the DTM multislot class indicated by the DTM GPRS Multi Slot Class field. 

The values '0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM GPRS multislot class 36, 37 or 38 
respectively if the Offset required f\e\6 indicates that the offset to is required; in all other cases those codepoints 
shall be interpreted as indicating DTM GPRS multislot class 31 , 32 or 33 respectively. 

Offset required (1 bit field) 

This field indicates whether the GPRS multislot class of the mobile station is such that the Timing Advance 

offset to is required (see 3GPP TS 45.002 [32]). It is coded as follows: 

The mobile station does not require the offset 

1 The mobile station requires the offset 

DTM EGPRS High Multi Slot Class (3 bit field) 

This field indicates the DTM EGPRS multislot capabilities of the MS. This field may be included only if the 

mobile station supports EGPRS DTM. This field is coded as the DTM GPRS High Multi Slot Class field. When 

this field is not present, the MS supports the DTM multislot class indicated by the DTM EGPRS Multi Slot Class 

field 

The values '0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM EGPRS multislot class 36, 37 or 38 
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respectively if the Offset required T\e\6 indicates tliat the Timing Advance offset to is required; in all other cases 
those codepoints shall be interpreted as indicating DTIVI EGPRS multislot class 31 , 32 or 33 respectively. 

The same multislot capability is applicable also for EGPRS2 if supported 

Repeated ACCH Capability (1 bit field) 

This field indicates whether the MS supports Repeated SACCH and Repeated Downlink FACCH (see 

3GPP TS 44.006 [19]). It is coded as follows: 

The mobile station does not support Repeated SACCH 

1 The mobile station supports Repeated SACCH and Repeated Downlink FACCH 

An MS that only supports Repeated Downlink FACCH shall set this bit field to '0'. 

GSM 710 Associated Radio Capability (4 bit field) 

See the semantic rule for the sending of this field. 

This field indicates whether GSM 710 band is supported and its associated radio capability. 

The radio capability contains the binary coding of the power class associated with the GSM 71 band (see 
3GPP TS 45.005 [33]). 

NOTE: The coding of the power class for GSM 71 in GSM 71 Associated Radio Capability is different to that 
used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements. 

T-GSM 810 Associated Radio Capability (4 bit field) 

See the semantic rule for the sending of this field. 

This field indicates whether T- GSM 810 band is supported and its associated radio capability. 

The radio capability contains the binary coding of the power class associated with the T-GSM 810 band (see 
3GPP TS 45.005 [33]). 

NOTE: The coding of the power class for T-GSM 81 in T-GSM 810 Associated Radio Capability is different to 
that used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements. 

Ciphering Mode Setting Capability (1 bit field) 

This field indicates whether the MS supports the Ciphering Mode Setting IE in the 

DTM ASSIGNMENT COMMAND message (see 3GPP TS 44.018 [84]). It is coded as follows: 

The mobile station does not support the Ciphering Mode Setting IE in the 
DTM ASSIGNMENT COMMAND message 

1 The mobile station supports the Ciphering Mode Setting IE in the DTM ASSIGNMENT COMMAND 
message 

Additional Positioning Capabilities (1 bit field) 

This field indicates whether the mobile station supports additional positioning capabilities which can be retrieved 
using RRLP. It is coded as follows: 

The mobile station does not support additional positioning capabilities which can be retrieved using 
RRLP 

1 The mobile station supports additional positioning capabilities which can be retrieved using RRLP. 

E-UTRA FDD support (1 bit field) 
Bit 

E-UTRA FDD not supported 

1 E-UTRA FDD supported 

E-UTRA TDD support (1 bit field) 
Bit 

E-UTRA TDD not supported 

1 E-UTRA TDD supported 

E-UTRA Measurement and Reporting support (1 bit field) 

This field indicates whether the mobile station supports E-UTRAN neighbouring cell measurements and 
measurement reporting in dedicated mode and, if the mobile station is DTM capable, also in dual transfer mode. 
If both "E-UTRA FDD support" and "E-UTRA TDD support" bits are set to '0', this field shall be set to '0'. If one 
of or both "E-UTRA FDD supporf'and "E-UTRA TDD support" bits are set to '1', this field may be set to '0' or 
'1'. It is coded as follows: 
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Bit 

E-UTRAN Neighbour Cell measurements and measurement reporting while having an RR connection 
not supported 

1 E-UTRAN Neighbour Cell measurements and measurement reporting while having an RR connection 
supported 

Priority-based reselection support (1 bit field) 

This field indicates whether the mobile station supports priority-based cell reselection. It Is coded as follows: 

Bit 

Priority-based cell reselection not supported 

1 Priority-based cell reselection supported 

UTRA CSG Cells Reporting (1 bit field) 

This field indicates whether the mobile station supports reporting of measurements and routing parameters (see 

3GPP TS 44.018 [84]) for UTRAN CSG cells in dedicated mode and, if the mobile station is DTM capable, also 

in dual transfer mode. This capability shall apply to each UTRA radio access mode supported by the mobile. It is 

coded as follows: 

Bit 

Reporting of UTRAN CSG cells not supported 

1 Reporting of UTRAN CSG cells supported 

VAMOS Level (2 bit field) 

This field indicates the VAMOS support of the MS and the VAMOS level supported. It is coded as follows: 

Bits 

21 

VAMOS not supported 

1 VAMOS I supported 

1 VAMOS II supported 

1 1 Unused. If received, the network shall interpret this as '1 0'. 

TIGHTER Capability (2 bit field) 

This field indicates Tightened Link Level Performance support in the MS (see 3GPP TS 45.005 [33]). The 
tightened performance applies to the traffic channels and signalling channels specified in 3GPP TS 45.005 [33]. 
The field is coded as follows: 

Bits 

21 

TIGHTER not supported 

1 TIGHTER supported for speech and signalling channels only 

1 TIGHTER supported for speech and signalling channels and for GPRS and EGPRS, but not for EGPRS2 
1 1 TIGHTER supported for speech and signalling channels and for GPRS, EGPRS and EGPRS2 

Selective Ciphering of Downlink SACCH (1 bit field) 

This field indicates whether the mobile station supports Selective Ciphering of Downlink SACCH (see 

3GPP TS 44.018 [84]). It is coded as follows: 

Bit 

Selective Ciphering of Downlink SACCH not supported 

1 Selective Ciphering of Downlink SACCH supported 



10.5.1.8 Spare Half Octet 

This element is used in the description of messages in clause 9 when an odd number of half octet type 1 information 
elements are used. This element is filled with spare bits set to zero and is placed in bits 5 to 8 of the octet unless 
otherwise specified. 

1 0.5.1 .9 Descriptive group or broadcast call reference 

The purpose of the Descriptive Group or Broadcast Call Reference is to provide information describing a voice group 
or broadcast call. The IE of the Descriptive Group or Broadcast Call Reference is composed of the group or broadcast 
call reference together with a service flag, an acknowledgement flag, the call priority and the group cipher key number. 
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The Descriptive Group or Broadcast Call Reference information element is coded as shown in figure 10.5.8/3GPP TS 
24.008 and Tablel0.5.8/3GPP TS 24.008 

The Descriptive Group or Broadcast Call Reference is a type 3 information element with 6 octets length. 



8 7 6 


5 


4 


3 2 1 


Group or broadcast call reference lEI 


Binary coding of the group or broadcast call reference 








SF 


AF 


call priority 


Ciphering information 


Spare 




octet 1 
octet 2 
octet 3 
octet 4 
octet 5 
octet 6 
Figure 10.5.8/3GPP TS 24.008 Descriptive Group or Broadcast Call Reference 
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Table 10.5.8/3GPP TS 24.008 Descriptive Group or Broadcast Call Reference 



Binary code of the group or broadcast call reference 

The length of the binary code has 27 bits which is encoded in the octet 2, 3, 4 and 

Bits 8,7,6 (octet 5). 

The highest bit of the BC is the bit 8 in the octet 2 and the lowest bit is allocated in 

the bit 6 in the octet 5. (see also 3GPP TS 23.003 [1 0]) 

SF Service flag (octet 5) 

Bit 

5 

VBS (broadcast call reference) 

1 VGCS (group call reference) 

AF Acknowledgement flag (octet 5), network to MS direction: 

Bit 

4 

acknowledgement is not required 

1 acknowledgement is required 

Call priority (octet 5) 
Bit 



2 



1 
1 



1 
1 



Ciphering 

Bit 

8 7 6 



1 
1 
1 
1 
1 
1 



no priority applied 
call priority level 4 
call priority level 3 
call priority level 2 
call priority level 1 
call priority level 
call priority level B 
call priority level A 

information (octet 6) 







1 

1 



no ciphering 
ciphering with 
ciphering with 
ciphering with 
ciphering with 
ciphering with 
ciphering with 
1 ciphering with 

ciphering with 

1 -'■-'--■■'■ "■- 


1 

1 


1 



ciphering with 
ciphering with 
ciphering with 
ciphering with 
ciphering with 
ciphering with 
ciphering with 



cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 
cipher key 



number 1 
number 2 
number 3 
number 4 
number 5 
number 6 
number 7 
number 8 
number 9 
number A 
number B 
number C 
number D 
number E 
number F 



AF Acknowledgement flag (octet 5), IVIS to network direction: 
Bit 4 is spare and shall be set to "0". 

Call priority (octet 5) 

Bits 1 to 3 are spare and shall be set to "0". 

Ciphering information (octet 6) 

Bits 5 to 8 are spare and shall be set to "0". 



10.5.1.10 Group Cipher Key Number 

The purpose of the Group Cipher Key Number is to provide information on the group cipher key to be used for 
ciphering and deciphering by the mobile station. 
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The Group Cipher Key Number information element is coded as shown in figure 10.5.9/3GPP TS 24.008 and 
Tablel0.5.9/3GPP TS 24.008 

The Group Cipher Key Number is a type 1 information element with 1 octet length. 



8 7 6 5 


4 3 2 1 


Group cipher key number 
lEI 


Group cipher l<ey number 



Figure 10.5.9/3GPP TS 24.008 Group Cipher Key Number 



Table 10.5.9/3GPP TS 24.008 Group Cipher Key Number 



Group cipher l<ey number 
Bit 

4 3 2 1 

spare 

1 cipher key number 1 

10 cipher l<ey number 2 

11 cipher key number 3 

10 cipher l<ey number 4 

10 1 cipher l<ey number 5 

110 cipher l<ey number 6 

111 cipher l<ey number 7 

cipher l<ey number 8 

1 cipher l<ey number 9 

1 cipher l<ey number A 

1 1 cipher l<ey number B 

1 cipher l<ey number C 
1 1 cipher l<ey number D 
1 1 cipher key number E 
1 1 1 cipher l<ey number F 



10.5.1.10a PD and SAPI $(CCBS)$ 

The purpose of the PD and SAPI information element is to provide information concerning Protocol Discriminators and 
Service Access Point Identifiers. 

The PD and SAPI information element is coded as shown in figure 10.5.10/3GPP TS 24.008 and table 10.5.10/3GPP TS 
24.008. 

The PD and SAPI is a type 3 information element with 2 octets length. 
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6 5 


4 3 2 


1 




PD and SAPI lEI 



spare 



spare 


SAPI 


PD 



octet 1 
octet 2 



Figurel 0.5.1 0/3GPP TS 24.008 
PD and SAPI information element 
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Table 1 0.5.1. 10/3GPP TS 24.008: PD and SAPI iniormation element 



SAPI: Service Access Point Identifier (octet 2) 



Bits 




6 5 







SAPIO 


1 


reserved 


1 


reserved 


1 1 


SAPI 3 



PD: Protocol Discriminator (octet 2) 

bits 4-1 

Encoded as specified in subclause 1 1 .2.1 of 3GPP TS 24.007 [20]. 



10.5.1.11 Priority Level 

The purpose of the Priority Level is to provide information defining the priority level requested or applied. The Priority 
Level IE may be included in CM_SERVICE_REQUEST, CALL_PROCEEDING and SETUP messages. 

The Priority Level information element is coded as shown in figure 10.5.11/3GPP TS 24.008 and table 10.5.11/3GPP 
TS 24.008. 

The Priority Level is a type 1 information element with 1 octet length. 





Priority Level 
lEI 



spare 


call priority 



octet 1 



Figure 10.5.11/3GPP TS 24.008 Priority Level 
Table 10.5.11/3GPP TS 24.008 Priority Level 



Call priority (octet 1) 


Bit 


3 2 1 


no priority applied 


1 call priority level 4 


1 call priority level 3 


1 1 call priority level 2 


1 call priority level 1 


1 1 call priority level 


1 1 call priority level B 


1 1 1 call priority level A 



1 0.5.1 .1 2 Core Network System Information (lu mode only) 

The purpose of the Core Network System /nformation is to provide the MS with actual parameter settings of system 
information parameters controlling MM and GMM functionality. The Core Network system information is included in 
specific information elements within some RRC messages sent to MS, see 3GPP TS 25.331 [23c]. 

NOTE: These lEs do not have an lEI or a length indicator, because these lEs are never present in any layer 3 
messages. Hence these lEs do not conform to the general IE rules defined in 3GPP TS 24.007 [20]. 

10.5.1.12.1 CN Common GSM-MAP NAS system information 

The purpose of the CN Common GSM-MAP NAS system information element is to provide the MS with actual 
parameter settings of parameters relevant for both MM and GMM functionality. The coding of the information element 
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identifier and length information is defined in the 3GPP TS 25.331 [23c]. Only the coding of the content is in the scope 
of the present document. 

The content of the CN common GSM-MAP NAS system information element is coded as shown in 
figure 10.5.1. 12. 1/3GPP TS 24.008 and table 10.5.1.12.1/3GPP TS 24.008. 

The length of this element content is two octets. The MS shall ignore any additional octets received. 
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7 


6 


5 4 


3 


2 


1 


LAC 



octet 1 
octet 2 

Figure 10.5.1. 12. 1/3GPP TS 24.008 Common system information element 
Table 10.5.1. 12. 1/3GPP TS 24.008: Common system information element 



LAC, Location Area Code (2 octet field) 

This field is the binary representation of the Location Area Code, see 3GPP TS 23.003 [10]. The LAC field 

consists of 16 bits. Bit 8 in octet 1 is the most significant bit and bit 1 in octet 2 is the least significant bit. 



10.5.1.12.2 CS domain specific system information 

The purpose of the CN domain specific GSM-MAP NAS system information element, when used for the CS domain, is 
to provide the MS with actual parameter settings of parameters relevant only for MM functionality. The coding of the 
information element identifier and length information is defined in the 3GPP TS 25.331 [23c]. Only the coding of the 
content is in the scope of the present document. 

For CS domain, the content of the CN domain specific GSM-MAP NAS system information element is coded as shown 
in figure 10.5.1.12.2/3GPP TS 24.008 and table 10.5.1. 12.2/3GPP TS 24.008. The length of this element content is two 
octets. The MS shall ignore any additional octets received. 
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octet 1 
octet 2 

Figure 10.5.1.12.2/3GPP TS 24.008 CS domain specific system information element 
Table 10.5.1 .12.2/3GPP TS 24.008: CS domain specific system information element 



T321 2 timeout value (1 octet field) 

The T3212 timeout field is coded as the binary representation of the timeout value for periodic updating in 

decihours. Bit 8 in octet 1 is the most significant bit and bit 1 in octet 1 is the least significant bit. 

Range: 1 to 255 

The value is used for infinite timeout value i.e. periodic updating shall not be used 

ATT, Attach-detach allowed (1 bitfield): 
Bit 1 

IVISs shall not apply IMSI attach and detach procedure. 

1 MSs shall apply IMSI attach and detach procedure 

The bits 2 - 8 of octet 2 are spare and shall be coded all zeros. 



10.5.1.12.3 PS domain specific system information 

The purpose of the CN domain specific GSM-MAP NAS system information element, when used for the PS domain, is to 
provide the MS with actual parameter settings of parameters relevant only for GMM functionality. The coding of the 
information element identifier and length information is defined in the 3GPP TS 25.331 [23c]. Only the coding of the 
content is in the scope of the present document. 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 1 427 ETSI TS 1 24 008 V1 0.1 0.0 (201 3-04) 

For PS domain, the content of the CN domain specific GSM-MAP NAS system information element is coded as shown in 
figure 10.5.1.12.3/3GPP TS 24.008 and table 10.5.1.12.3/3GPP TS 24.008. The length of this element content is two 
octets. The MS shall ignore any additional octets received. 



octet 1 
octet 2 



Figure 10.5.1.12.3/3GPP TS 24.008 PS domain specific system information element 
Table 10.5.1.12.3/3GPP TS 24.008: PS domain specific system information element 



8 


7 


6 5 


4 


3 


2 


1 


RAG 






Spare 






INMOI 


1 NMO 



RAC, Routing Area Code (8 bit field) 

This field is the binary representation of the Routing Area Code, see 3GPP TS 23.003 [10]. Bit 8 in octet 1 

is the most significant bit and bit 1 in octet 1 is the least significant bit. 

NMO, Network Mode of Operation (1 bit field) 

This field is the binary representation of the Network Mode of Operation, see 3GPP TS 23.060 [74] 

Bit 1 

Network Mode of Operation I 

1 Network Mode of Operation II 

NMO I, Networic Mode of Operation I (1 bit field) 

This field is the binary representation of whether the Network Mode of Operation I is applicable for the MS 

configured for NMO_l_Behaviour, see 3GPP TS 24.368 [1 35] or 3GPP TS 31 .1 02 [1 1 2] 

Bit 2 

Network Mode of Operation indicated in Bit 1 (NMO, Network Mode of Operation) is used for MS 
configured for NMO_l_Behaviour 

1 Network Mode of Operation I is used for MS configured for NMO_l_Behavlour 

The bits 3 - 8 of octet 2 are spare and shall be coded all zeros. 



10.5.1.13 PLMNIist 

The purpose of the PLMN List information element is to provide a list of PLMN codes to the mobile station. 

The PLMN List information element is coded as shown in figure 10.5.13/3GPP TS 24.008 and table 10.5.13/3GPP TS 
24.008. 

The PLMN List is a type 4 information element with a minimum length of 5 octets and a maximum length of 47 octets. 
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PLMN List lEI 


Length of PLMN List contents 


MCCdigit2, PLMN 1 


MCCdigit1,PLMN 1 


MNCdigitS, PLMN 1 


MCC digit 3, PLMN 1 


MNCdigit2, PLMN 1 


MNC digit 1, PLMN 1 









octet 1 
octet 2 
octet 3 
octet 4 
octet 5 







MCC digit 2, PLMN 15 


MCC digit 1, PLMN 15 


MNC digit 3, PLMN 15 


MCC digit 3, PLMN 15 


MNC digit 2, PLMN 15 


MNC digit 1, PLMN 15 



octet 45 
octet 46 
octet 47 
Figure 10.5.13/3GPP TS 24.008 PZ./WA/Z.;sMnformation element 

Table 1 0.5.1 3/3GPP TS 24.008: PLMW Z.;sMnformation element 



MCC, Mobile country code (octet 3, octet 4 bits 1 to 4) 
The MCC field is coded as in ITU-T Rec. E212, Annex A. 

MNC, Mobile network code (octet 5, octet 4 bits 5 to 8). 

The coding of this field is the responsibility of each administration but BCD coding 
shall be used. The MNC shall consist of 2 or 3 digits. For PCS 1 900 for NA, Federal 
regulation mandates that a 3-digit MNC shall be used. However a network operator 
may decide to use only two digits in the MNC over the radio interface. In this case, 
bits 5 to 8 of octet 4 shall be coded as "1111 ". Mobile equipment shall accept MNC 
coded in such a way. 



10.5.1.14 NAS container for PS HO 

The purpose of the NAS container for PS HO information element is to indicate the NAS specific information for the PS 
handover to A/Gb mode. The NAS container for PS HO information element is included in the PS HO command 
message, see 3GPP TS 44.060 [76]. The coding of the information element identifier and length information is defined 
in 3GPPTS 44.060 [76]. 

The content of the NAS container for PS HO information element is coded as shown in figure 10.5. 1. 14/3GPP TS 
24.008 and table 10.5.1.14/3GPP TS 24.008. The length of this information element is 5 octets. The MS shall ignore 
any additional octets received. 
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lOV-UI value (High-order octet) 
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lOV-UI value (continued) 
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lOV-UI value (continued) 
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lOV-UI value (Low-order octet) 


octet 5 



Figure 10.5.1 .14/3GPP TS 24.008 NAS container for PS HO information element 



Table 10.5.1 .14/3GPP TS 24.008: NAS container for PS HO information element 



Type of ciphering algorithm (octet 1 , bits 
Bits 



ciphering not used 
GPRS Encryption Algorithm 
GPRS Encryption Algorithm 
GPRS Encryption Algorithm 
GPRS Encryption Algorithm 
GPRS Encryption Algorithm 
GPRS Encryption Algorithm 
GPRS Encryption Algorithm 



3 


2 
























1 








1 




1 








1 







1 


1 





1 


1 





1 to 3) 



GEA/1 
GEA/2 
GEA/3 
GEA/4 
GEA/5 
GEA/6 
GEA/7 



Bit 4 of octet 1 is spare and shall be coded as zero. 

old XID (octet 1, bit 5): 

With this bit the network indicates, which LLC layer parameters and layer-3 parameters the MS shall use in 

the target cell after it has performed the Reset of LLC and SNDCP. 

Bit 5 

The MS shall perform a Reset of LLC and SNDCP without old XID indicator as specified in 
3GPP TS 44.064 [78a] and 3GPP TS 44.065 [78]. 

1 The MS shall perform a Reset of LLC and SNDCP with old XID indicator as specified in 
3GPP TS 44.064 [78a] and 3GPP TS 44.065 [78]. 

The bits 6 - 8 of octet 1 are spare and shall be coded all zeroes. 

lOV-UI value (octet 2 to 5) 

The lOV-UI value consists of 32 bits, the format is defined in 3GPP TS 44.064 [78a]. 



1 0.5.1 .1 5 MS network feature support 

The purpose of the MS network feature support information element is to indicate support of mobihty management 
parameters during the tracking area updating, location updating, routing area updating, IMS I attach, GPRS attach, and 
EPS attach procedures. 

The MS network feature support information element is coded as shown in figure 10.5.1.15/3GPP TS 24.008 and 
table 10.5.1.15/3GPPTS 24.008. 

The MS network feature support information element is a type 1 information element. 



octet 1 



8 7 6 5 
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MS network feature support 
lEI 
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extend 
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period! 
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Figure 10.5.1 .15/3GPP TS 24.008: IVIS network feature support information element 
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Table 10.5.1.15/3GPP TS 24.008: MS network feature support information element 



Extended periodic timers (octet 1 ) 

Bit 
1 

IVIS does not support tiie extended periodic timer in tliis domain 

1 IVIS supports the extended periodic timer in this domain 

The relevant extended periodic timer is T3212 for MM messages, T3312 for GMM 
messages, and T3412 for EMM messages. 

Bits 4, 3 and 2 of octet 1 are spare and shall be coded as zero. 



10.5.2 Radio Resource management information elements. 

See 3GPPTS 44.018 [84]. 

10.5.3 Mobility management information elements. 
10.5.3.1 Authentication parameter RAND 

The purpose of the Authentication Parameter RAND information element is to provide the mobile station with a non- 
predictable number to be used to calculate the authentication response signature SRES and the ciphering key Kc (for a 
GSM authentication challenge), or the response RES and both the ciphering key CK and integrity key IK (for a UMTS 
authentication challenge). 

The Authentication Parameter RAND information element is coded as shown in figure 10.5.75/3GPP TS 24.008 and 
table 10.5.89/3GPP TS 24.008. 

The Authentication Parameter RAND is a type 3 information element with 17 octets length. 
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Figure 10.5.75/3GPP IS 24.008 Authentication Parameter RAND information element 
Table 10.5.89/3GPP TS 24.008: Auttientication Parameter RAND information element 



RAND value (octet 2, 3,... and 17) 

The RAND value consists of 128 bits. Bit 8 of octet 2 is the most significant bit while bit 1 of octet 

1 7 is the least significant bit. 



10.5.3.1.1 



Authentication Parameter AUTN (UMTS and EPS authentication challenge) 



The purpose of \ht Authentication Parameter AUTN infoTvaation element is to provide the MS with a means of 
authenticating the network. 

The Authentication Parameter AUTN infoixnation element is coded as shown in figure 10.5.75. 1/3GPP TS 24.008 and 
table 10.5.89. 1/3GPPTS 24.008. 

The Authentication Parameter AUTN is a type 4 information element with a length of 18 octets. 
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8 


7 


6 5 4 3 


2 


1 


Authentication Parameter AUTN lEI 


Length of AUTN contents 


AUTN 



octet 1 
octet 2 
octet 3 



octet 1 8 



Figure 1 0.5.75. 1/3GPP TS 24.008 Authentication Parameter AUTN iniormation element (UMTS and 

EPS authentication challenge) 



Table 1 0.5.89.1 /3GPP TS 24.008 Autiientication Parameter AUTN iniormation element (UMTS and EPS 

authentication challenge) 



AUTN value (octets 3 to 18) 

The AUTN consists of (SQN xor AK)||AIVIF||MAC 

=48+16+64 bits 

(see 3GPPTS 33.102 [5a]) 

Bit 8 of octet 9 is the "separation bit" of the AIVIF field (see 3GPP TS 33.401 [123]). 



10.5.3.2 Authentication Response parameter 

The purpose of the authentication response parameter information element is to provide the network with the 
authentication response calculated in the SIM/USIM. 

The Authentication Parameter SRES information element is coded as shown in figure 10.5.76/3GPP TS 24.008 and 
tables 10.5.90 a & b /3GPP TS 24.008. 

The Authentication Response Parameter is a type 3 information element with 5 octets length. In a GSM authentication 
challenge, the response calculated in the SIM/USIM (SRES) is 4 bytes in length, and is placed in the Authentication 
Response Parameter information element. 

In a UMTS authentication challenge, the response calculated in the USIM (RES) may be up to 16 octets in length. The 4 
most significant octets shall be included in the Authentication Response Parameter information element. The remaining 
part of the RES shall be included in the Authentication Response Parameter (extension) IE (see subclause 10.5.3.2.1) 



Authentication Response parameter I El 



SRES value or most significant 
4 octets of RES 



octet 1 



octet 2 



octet 5 



Figure 10.5.76/3GPP TS 24.008 Autiientication Response Paramefer information element 



Table 10.5.90a/3GPP TS 24.008: Autiientication Response Parameter information element 
(SRES) (GSM authentication challenge only) 



SRES value (octet 2, 3, 4 and 5) 

The SRES value consists of 32 bits. Bit 8 of octet 2 is the most significant bit while bit 1 of octet 5 

is the least significant bit. 
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Table 10.5.90b/3GPP TS 24.008: Authentication Response Parameter information element (RES) 

(UIVITS authentication challenge only) 



RES value (octet 2, 3, 4 and 5) 

This contains the most significant 4 octets of RES 

If RES>4 octets, the remaining octets of RES shall appear in the Authentication Response 

Parameter (extension) IE (see subclause 10.5.3.2.1) 



10.5.3.2.1 Authentication Response Parameter (extension) (UMTS authentication challenge 

only) 

This IE is included if the authentication response parameter RES is longer than 4 octets (UMTS only) and therefore 
does not fit in the Authentication Response Parameter field (see 10.5.3.2). 

The Authentication Response parameter (extension) IE is coded as shown in figure 10.5.76. 1/3GPP TS 24.008 and table 
10.5.90.1/3GPPTS 24.008. 

The Authentication Response parameter (extension) IE is a type 4 information element with a minimum length of 3 
octets and a maximum length of 14 octets. 



Authentication Response (extension) lEI 



Length of Authentication Response contents 



RES (all but 4 most significant octets) 



octet 1 
octet 2 
octet 3 



octet 1 4 



Figure 10.5.76.1/3GPP TS 24.008 Authentication Response Parameter (extension) information 

element (UMTS authentication challenge only) 



Table 10.5.90.1/3GPP TS 24.008: Authientication Response Parameter (extension) information element 

(RES) 



RES (extension) value (octet 3 to 14) 

This contains all but the 4 most significant octets of RES 



10.5.3.2.2 



Authentication Failure parameter (UMTS and EPS authentication challenge) 



The purpose of the Authentication Failure parameter information element is to provide the network with the necessary 
information to begin a re-authentication procedure (see 3GPP TS 33. 102 [5a]) in the case of a 'Synch failure', following 
a UMTS or EPS authentication challenge. 

The Authentication Failure parameter IE is coded as shown in figure 10.5.76.2/3GPP TS 24.008 and table 
10.5.90.2/3GPP TS 24.008. 

The Authentication Failure parameter IE is a type 4 information element with a length of 16 octets. 
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8 


7 6 5 4 3 2 1 


Authentication Failure parameter lEI 


Lengtii ofAuthentication Failure parameter contents 


Authentication Failure parameter 



octet 1 
octet 2 
octet 3 



octet 1 6 



Figure 10.5.76.2/3GPP TS 24.008 Authentication Failure parameter information element (UMTS and 

EPS authentication challenge) 

Table 10.5.90.2/3GPP TS 24.008: Authentication Failure parameter information element 



Authentication Failure parameter value (octet 3 to 16) 
This contains AUTS (see 3GPP TS 33.1 02 [5a]) 



1 0.5.3.3 CM service type 

The purpose of the CM Service Type information element is to specify which service is requested from the network. 

The CM Service Type information element is coded as shown in figure 10.5.77/3GPP TS 24.008 and 
table 10.5.91/3GPP TS 24.008. 

The CM Service Type is a type 1 information element. 



CIVI service type lEI 



service type 



octet 1 



Figure 10.5.77/3GPP TS 24.008 CM Service Type information element 
Table 10.5.91/3GPP TS 24.008: CM Service Type information element 



Service type (octet 1) 


Bits 






4 3 2 


1 







1 


Mobile originating call establishment or packet mode connection 
establishment 


1 





Emergency call establishment 


1 





Short message service 


1 





Supplementary service activation 


1 


1 


Voice group call establishment 


1 1 





Voice broadcast call establishment 


1 1 


1 


Location Services (NOTE) 


All other values are reserved. 


NOTE: 


this service type shall only be used by a type A LMU if the MM 




connection was requested for the transmission of LCS signalling 




messages specified in 3GPP TS 44.071 [23a]. 



10.5.3.4 Identity type 

The purpose of the Identity Type information element is to specify which identity is requested. 

The Identity Type information element is coded as shown in figure 10.5.78/3GPP TS 24.008 and table 10.5.92/3GPP TS 
24.008. 
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The Identity Type is a type 1 information element. 



Identity type lEI 



spare 


type of identity 



octet 1 

Figure 10.5.78/3GPP TS 24.008 Identity Type information element 
Table 10.5.92/3GPP TS 24.008: Identity Type information element 



Type of identity (octet 1 


Bits 




3 2 1 




1 


IMSI 


1 


IMEI 


1 1 


IMEISV 


1 


IMSI 



All other values are reserved. 



10.5.3.5 Location updating type 

The purpose of the Location Updating Type information element is to indicate whether a normal updating, a periodic 
updating or an IMSI attach is wanted. It may also indicate that a follow-on request has been received from the mobile 
station CM layer. 

The Location Updating Type information element is coded as shown in figure 10.5.79/3GPP TS 24.008 and 
table 10.5.93/3GPP TS 24.008. 

The Location Updating Type is a type 1 information element. 



8 



1 



Location updating 
type lEI 


FOR 



spare 


LUT 



octet 1 

Figure 10.5.79/3GPP TS 24.008 Location Updating Type information element 
Table 10.5.93/3GPP TS 24.008: Location Updating Type information element 



LUT (octet 


) 


Bits 




2 1 







Normal location updating 


1 


Periodic updating 


1 


IMSI attach 


1 1 


Reserved 


FOR (octet 


1) 


Tfie Follow-On Request bit (FOR) is coded as follows: 


Bits 




4 







No follow-on request pending 


1 


Follow-on request pending 



10.5.3.5a Networl< Name 

The purpose of this information element is to pass a text string to the mobile station. 
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The Network Name information element is coded as shown in figure 10.5.80/3GPP TS 24.008 and table 10.5.94/3GPP 
TS 24.008. 

If the coding scheme UCS2 is used and Chinese-Japanese-Korean- Vietnamese (CJKV) ideographs as defined in 
ISO/IEC 10646 [72] are received in the text string, the MS shall use the MCC of the PLMN from which it received the 
network name information element to determine the language for those CJKV ideographs as specified in 
table 10.5.93a/3GPP TS 24.008: 

Table 10.5.93a/3GPP TS 24.008: MCC to CJKV ideograph language mapping table 



MCC(s) 


Country/Region 


Language 
(C, J, K, or V) 


460, 461 


Mainland China 


Chinese-G 


466 


Taiwan 


Chinese-T 


454 


HongKong 


Chinese-T 


455 


Macao 


Chinese-T 


440, 441 


Japan 


J (Kanji) 


450, 467 


Korea 


K (Hanja) 


452 


Vietnam 


V (Chunom) 



NOTE: This is due to CJKV ideograph language ambiguity in UCS2, in the sense that the same hexadecimal code 
can be mapped to different character displays dependent on the used language. The coding of CJKV 
ideographs itself does not allow to discriminate the CJKV ideograph language. 

The Network Name is a type 4 information element with a minimum length of 3 octets. No upper length limit is 
specified except for that given by the maximum number of octets in a L3 message (see 3GPP TS 44.006 [19]). 



ext 
1 



Network Name lEI 



Length of Network Name contents 



coding scheme 



Add 
CI 



Text String 



Number of spare 
bits in last octet 



octet 1 
octet 2 
octet 3 
octet 4 

octet n 



Figure 10.5.80/3GPP TS 24.008 Network Name information element 
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Table 10.5.94/3GPP TS 24.008 Network Name information element 



Number of spare bits in last octet (octet 3, bits 1 to 3) 

2 1 

1 bit 8 is spare and set to "0" in octet n 

1 bits 7 and 8 are spare and set to "0" in octet n 

1 1 bits 6 to 8(inclusive) are spare and set to "0" in octet n 

1 bits 5 to 8(inclusive) are spare and set to "0" in octet n 
1 1 bits 4 to 8(inclusive) are spare and set to "0" in octet n 
1 1 bits 3 to 8(inclusive) are spare and set to "0" in octet n 
1 1 1 bits 2 to 8(inclusive) are spare and set to "0" in octet n 

this field carries no information about the number of spare bits in octet n 

Add CI (octet 3, bit 4) 

The IVIS should not add the letters for the Country's Initials to the text string 

1 The MS should add the letters for the Country's Initials and a separator 
(e.g. a space) to the text string 

Coding Scheme (octet 3, bits 5-7) 

Cell Broadcast data coding scheme, GSM default alphabet, language unspecified, defined in 3GPP TS 

23.038 [8b] 
1 UCS2(16bit)[72] 

1 

to reserved 

1 1 1 

Text String (octet 4 to octet n, inclusive) 

Encoded according to the Coding Scheme defined by octet 3, bits 5-7 



10.5.3.6 Reject cause 

The purpose of the Reject Cause information element is to indicate the reason why a request from the mobile station is 
rejected by the network. 

The Reject Cause information element is coded as shown in figure 10.5.81/3GPP TS 24.008 and 
table 10.5.95/3GPP TS 24.008. 

The Reject Cause is a type 3 information element with 2 octets length. 



octet 1 
octet 2 
Figure 10.5.81/3GPP TS 24.008 Reject Cause information element 



8 


7 


8 


5 4 


3 


2 


1 


Reject cause IE! 


reject cause value 
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Table 10.5.95/3GPP TS 24.008: Reject Cause information element 



Reject 


cause 


value (octet 2) 




Bits 
















8 7 


6 


5 


4 


3 


2 





















1 





IMS! unknown in HLR 

















1 




Illegal MS 






















IIVISI unknown in VLB 





















IIVIEI not accepted 
















1 





Illegal ME 











1 





1 




PLMN not allowed 











1 










Location Area not allowed 











1 









Roaming not allowed in this location area 











1 




1 




No Suitable Cells In Location Area 





















Network failure 





















MAC failure 




















Synch failure 















1 





Congestion 















1 




GSM authentication unacceptable 










1 










Not authorized for this CSG 






















Service option not supported 



















1 


Requested service option not subscribed 
















1 





Service option temporarily out of order 













1 


1 





Call cannot be identified 







1 














} 


to 














} retry upon entry into a new cell 







1 


1 


1 


1 




} 


1 





1 


1 


1 


1 




Semantically incorrect message 


1 



















Invalid mandatory information 


1 


















Message type non-existent or not implemented 


1 













1 





Message type not compatible with the protocol state 


1 













1 




Information element non-existent or not implemented 


1 










1 








Conditional IE error 


1 










1 







Message not compatible with the protocol state 


1 







1 


1 


1 




Protocol error, unspecified 


Any other value received by tlie mobile station shall be treated as 001 001 0, 


'Service option temporarily out of order'. Any other value received by the network 


shall be treated as 0110 11 11, 


'Protocol error, unspecified'. 


NOTE 




The listed reject cause values are defined in Annex G. 



10.5.3.7 



Follow-on Proceed 



The purpose of the Follow-on Proceed information element is to indicate that an MM connection may be estabUshed on 
an existing RR connection. 

The Follow-on Proceed information element is coded as shown in figure 10.5.82/3GPP TS 24.008. 

The Follow-on Proceed is a type 2 information element. 



Follow-on Proceed lEI 



octet 1 



Figure 10.5.82/3GPP TS 24.008 Follow-on Proceed information element 

10.5.3.8 Time Zone 

The purpose of this information element is to encode the offset between universal time and local timein steps of 15 
minutes. 
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The Time Zone information element is coded as shown in figure 10.5.83/3GPP TS 24.008 and 
table 10.5.96/3GPP TS 24.008. 

The Time Zone is a type 3 information element with a length of 2 octets. 



8 


7 


6 


5 4 3 


2 


1 


Time Zone lEI 


Time Zone 



octet 1 



octet 2 



Figure 10.5.83/3GPP TS 24.008 Time Zone information element 
Table 10.5.96/3GPP TS 24.008 Time Zone information element 



Time Zone (octet 2, bits 1-8) 

This field uses the same format as the Timezone field used in the TP-Service-Centre-Time-Stamp, 

which is defined in 3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 

[89] 



1 0.5.3.9 Time Zone and Time 

The purpose of the timezone part of this information element is to encode the offset between universal time and local 
time in steps of 15 minutes. 

The purpose of the time part of this information element is to encode the universal time at which this information 
element may have been sent by the network. 

The Time Zone and Time information element is coded as shown in figure 10.5.84/3GPP TS 24.008 and 
table 10.5.97/3GPP TS 24.008. 

The Time Zone and Time is a type 3 information element with a length of 8 octets. 



Time Zone and Time lEI 



Year 



Month 



Day 



Hour 



Minute 



Second 



Time zone 



octet 1 
octet 2 
octet 3 
octet 4 
octet 5 
octet 6 
octet 7 
octet 8 



Figure 10.5.84/3GPP TS 24.008 Time Zone and Time information element 
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Table 10.5.97/3GPP TS 24.008 Timezone and Time information element 



Year (octet 2, bits 1 -8) 

This field uses the same format as the Year field used in the TP-Service-Centre-Time-Stamp, which is defined in 
3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89] 

IVIonth (octet 3, bits 1-8) 

This field uses the same format as the Month field used in the TP-Service-Centre-Time-Stamp, which is defined in 

3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]. 

Day (octet 4, bits 1 -8) 

This field uses the same format as the Day field used in the TP-Service-Gentre-Time-Stamp, which is defined in 3GPP 

TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]. 

Hour (octet 5, bits 1-8) 

This field uses the same format as the Hour field used in the TP-Service-Gentre-Time-Stamp, which is defined in 

3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]. 

IVlinute (octet 6, bits 1-8) 

This field uses the same format as the iVIinute field used in the TP-Service-Centre-Time-Stamp, which is defined in 

3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]. 

Second (octet 7, bits 1 -8) 

This field uses the same format as the Second field used in the TP-Service-Centre-Time-Stamp, which is defined in 

3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]. 

Time Zone (octet 8, bits 1-8) 

This field uses the same format as the Time Zone field used in the TP-Service-Centre-Time-Stamp, which is defined in 

3GPP TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]. 



NOTE: Due to ambiguities in earlier versions of the protocol specifications, some mobile stations may interpret 
the received NITZ time as local time. This may result in incorrect time settings in the mobile. 

10.5.3.10 CIS permission 

The purpose of the CTS permission information element is to indicate that the mobile station is allowed to use GSM- 
Cordless Telephony System in the Location Area. The CTS permission information element is coded as shown in 
figure 10.5.84a/3GPP TS 24.008. 

The CTS permission is a type 2 information element. 



CTS Permission lEI octet 1 



Figure 10.5.84a/3GPP TS 24.008 CTS permission information element 
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10.5.3.11 LSA Identifier 

This element uniquely identifies a LSA. 

The LSA Identifier information element is coded as shown in figure 10.68c/3GPP TS 24.008. 

The LSA Identifier is a type 4 information element with a length of 2 or 5 octets. 



8 


7 


6 5 4 3 


2 


1 


1 LSA Identifier lEI 


Lengtii of LSA Identifier contents 


LSA ID 


LSA ID cent. 


LSA ID cent. 



octet 1 
octet 2 
octet 3 
octet 4 
octet 5 
Figure 10.68c/3GPP TS 24.008 LSA /c/enf/ffer information element 

If the Length = 0, then no LSA ID is included. This is used to indicate that the MS has moved to an area 
where there is no LSA available for that MS. 

Octets 3-5 are coded as specified in 3GPP TS 23.003 [10], Identification of Localised Service Area'. Bit 8 of octet 3 is 
the most significant bit. 

1 0.5.3.1 2 Daylight Saving Time 

The purpose of this information element is to encode the Daylight Saving Time in steps of 1 hour. 

The Daylight Saving Time information element is coded as shown in figure 10.5.84b/3GPP TS 24.008 and 
table 10.5.97a/3GPP TS 24.008. 

The Daylight Saving Time is a type 4 information element with a length of 3 octets. 



8 


7 6 5 4 3 


2 1 


Daylight Saving Time lEI 


Length of Daylight Saving Time contents 





spare 



value 



octet 1 
octet 2 
octet 3 
Figure 10.5.84b/3GPP TS 24.008 Daylight Saving Time information element 

Table 10.5.97a/3GPP TS 24.008: Dayiigtit Saving Time information element 



Daylight Saving Time value (octet 3) 

Bits 

2 1 

No adjustment for Daylight Saving Time 

1 +1 hour adjustment for Daylight Saving Time 

1 +2 hours adjustment for Daylight Saving Time 
1 1 Reserved 
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10.5.3.13 Emergency Number List 

The purpose of this information element is to encode emergency number(s) for use within the country (as indicated by 
MCC) where the IE is received. 

The Emergency Number List information element is coded as shown in figure 10.5.84c/3GPP TS 24.008. 

The Emergency Number List IE is a type 4 information element with a minimum length of 5 octets and a maximum 
length of 50 octets. 



8 7 6 5 


4 3 2 1 


Emergency Number List lEI 


Length of Emergency Number List IE contents 


Length of 1^' Emergency Number information note 1) 


spare Emergency Service Category Value (see 
Table 10.5.135d/3GPPTS 24.008) 


Number digit 2 


Number digit 1 


Number digit 4 


Number digit 3 






note 3) 




Length of 2™ Emergency Number information note 1) 


spare Emergency Service Category Value (see 
Table 10.5.135d/3GPPTS 24.008) 


Number digit 2 


Number digit 1 


Number digit 4 


Number digit 3 






note 3) 






Length of xth Emergency Number information note 1) 


spare Emergency Service Category Value (see 
Table 10.5.135d/3GPPTS 24.008) 


Number digit 2 


Number digit 1 


Number digit 4 


Number digit 3 






note 3) 





octet 1 
octet 2 
octet 3 
octet 4 

octet 5 
note 2) 
octet 6* 



octet j-r 

octet j* 
Octet j+1* 

octet j+2* 

note 2) 

octet j+3* 



octet j+k* 



octet n* 
Octet n+r 

octet n+2* 

note 2) 
octet n+3* 



octet n+m* 



NOTE 1 : The length contains the number of octets used to encode the Emergency Service Category Value and the 

Number digits. 
NOTE 2: The number digit(s) in octet 5 precedes the digit(s) in octet 6 etc. The number digit, which would be 

entered first, is located in octet 5, bits 1 to 4. The contents of the number digits are coded as shown in 

table 10.5.118/3GPP TS 24.008. 
NOTE 3: If the emergeny number contains an odd number of digits, bits 5 to 8 of the last octet of the respective 

emergency number shall be filled with an end mark coded as "1 111". 

Figure 10.5.84c/3GPP TS 24.008 Emergency A/umber L/sf information element 
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10.5.3.14 Additional update parameters 

The purpose of the Additional update parameters information element is to provide additional information during the 
location updating procedure and during MM connection establishment. 

The Additional update parameters information element is coded as shown in figure 10.5.84d/3GPP TS 24.008 and 
table 10.5.97b/3GPP TS 24.008. 

The Additional update parameters information element is a type 1 information element. 



8 7 6 5 


4 


3 


2 


1 


Additional update parameters 
lEI 



Spare 



Spare 


CSMO 


CSMT 



octet 1 

Figure 10.5.84d/3GPP TS 24.008: Additional update parameters information element 
Table 10.5.97b/3GPP TS 24.008: Additional update parameters information element 



Additional update parameters value (octet 1 , bit 1 to 4) 

CSMT (1 bit field) 

Bit 
1 

No additional information. 

1 CS fallback mobile terminating call 

CSMO (1 bit field) 

Bit 
2 

No additional information. 

1 CS fallback mobile originating call 

Bits 4 and 3 of octet 1 are spare and shall be all coded as zero. 



10.5.3.15 Void 

10.5.3.16 MM Timer 

The purpose of the MM timer information element is to specify MM specific timer values, e.g. for the timer T3247. 

The MM timer is a type 4 information element with 3 octets length. 

The MM f/mer information element is coded as shown in figure 10.5.3. 16- 1/3GPP TS 24.008 and table 10.5.3.16- 
1/3GPP TS 24.008. 



MM Timer lEI 



Length of MM Timer contents 



MM Timer value 



octet 1 
octet 2 
octet 3 



Figure 10.5.3.16-1/3GPP TS 24.008: MM T/mef information element 
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Table 10.5.3. 16-1/3GPP TS 24.008: MM T/Tner information element 



Timer value (octet 3) 

Bits 5 to 1 represent tine binary coded timer value. 

Bits 6 to 8 defines the timer value unit for the MM timer as follows: 

Bits 

876 

value is incremented in multiples of 2 seconds 

1 value is incremented in multiples of 1 minute 

1 value is incremented in multiples of decihours 

1 1 1 value indicates that the timer is deactivated. 

Other values shall be interpreted as multiples of 1 minute in this version of the 
protocol. 

The value indicated is contructed by multiplying the value in bits 5 to 1 with the timer 
value unit in bits 8 to 6, unless the timer value unit indicates the timer being 
deactivated. 



1 0.5.4 Call control information elements 



10.5.4.1 



Extensions of codesets 



There is a certain number of possible information element identifier values using the formatting rules described in 
subclause 10.5: 128 from the type 3 & 4 information element format and at least 8 from the type 1 & 2 information 
element format. 

One value in the type 1 format is specified for shift operations described below. One other value in both the type 3 & 4 
and type 1 format is reserved. This leaves 133 information element identifier values available for assignment. 

It is possible to expand this structure to eight codesets of 133 information element identifier values each. One common 
value in the type 1 format is employed in each codeset to facilitate shifting from one codeset to another. The contents of 
this shift information element identifies the codeset to be used for the next information element or elements. The 
codeset in use at any given time is referred to as the "active codeset". By convention, codeset is the initially active 
codeset. 

Two codeset shifting procedures are supported: locking shift and non-locking shift. 

Codeset 5 is reserved for information elements reserved for national use. 

Codeset 6 is reserved for information elements specific to the local network (either public or private). 

Codeset 7 is reserved for user-specific information elements. 

The coding rules specified in subclause 10.5 shall apply for information elements belonging to any active codeset. 

The mobile station and the network shall not apply the "comprehension required" scheme (see 3GPP TS 24.007 [20]) to 
information elements belonging to codesets different from codeset 0. 

lEIs with bits 5, 6, 7 and 8 all set to zero should not be allocated for new optional information elements in codesets 
different from codeset 0, because there are legacy mobile stations that apply the "comprehension required" scheme also 
to these information elements, e.g. if such a mobile station receives a SETUP message containing an unknown 
information element from codeset 5 with an lEI with bits 5, 6, 7 and 8 all set to zero, then the mobile station will release 
the call. 

Transitions from one active codeset to another (i.e. by means of the locking shift procedure) may only be made to a 
codeset with a higher numerical value than the codeset being left. 
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An information element belonging to codeset 5, 6 or 7 may appear together with information elements belonging to 
codeset 0, by using the non-locking shift procedure (see subclause 10.5.4.3). 

A user or network equipment shall have the capability to recognize a shift information element and to determine the 
length of the following information element, although the equipment need not be able to interpret and act on the content 
of the information element. This enables the equipment to determine the start of the subsequent information element. 

1 0.5.4.2 Locking shift procedure 

The locking shift procedure employs an information element to indicate the new active codeset. The specified codeset 
remains active until another locking shift information element is encountered which specifies the use of another codeset. 
For example, codeset is active at the start of message content analysis. If a locking shift to codeset 5 is encountered, 
the next information elements will be interpreted according to the information element identifiers assigned in codeset 5, 
until another shift information element is encountered. This procedure is used only to shift to a higher order codeset 
than the one being left. 

The locking shift is valid only within that message which contains the locking shift information element. At the start of 
every message content analysis, the active codeset is codeset 0. 

The locking shift information element uses the type 1 information element format and coding shown in 
figure 10.5.85/3GPP TS 24.008 and table 10.5.98/3GPP TS 24.008. 



8 


7 6 5 


4 


3 


2 1 


1 


1 
(Shift identifier) 





New codeset 
identification 



octet 1 



"0" in tliis position indicates locl<ing sliift 
Figure 10.5.85/3GPP TS 24.008 Locking shift element 

Table 10.5.98/3GPP TS 24.008: Locking shift element 



Codeset identification (octet 


1): 


Bits 






3 2 1 









not applicable 




1 


} 




to 


} reserved 




1 


} 




1 1 


codeset 5: 


information elements for national use 


1 1 


codeset 6: 


information elements specific to the local networl< 
(either public or private) 


1 1 1 


codeset 7: 


user-specific information elements 



10.5.4.3 Non-locking shift procedure 

The non-locking shift procedure provides a temporary shift to the specified lower or higher codeset. The non-locking 
shift procedure uses a type 1 information element to indicate the codeset to be used to interpret the next information 
element. After the interpretation of the next information element, the active codeset is again used for interpreting any 
following information elements. For example, codeset is active at the beginning of message content analysis. If a non- 
locking shift to codeset 6 is encountered, only the next information element is interpreted according to the information 
element identifiers assigned in codeset 6. After this information element is interpreted, codeset will again be used to 
interpret the following information elements. A non-locking shift information element indicating the current codeset 
shall not be regarded as an error. 

A locking shift information element shall not follow directly a non-locking shift information element. If this 
combination is received, it shall be interpreted as though a locking shift information element had been received. 

The non-locking shift information element uses the type 1 information format and coding shown in figure 10.5.86/3GPP 
TS 24.008 and table 10.5.99/3GPP TS 24.008. 
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"1" in this position indicates non-locl<ing shift 
Figure 10.5.86/3GPP TS 24.008 Non-locking shift element 

Table 10.5.99/3GPP TS 24.008: Non-locking shift element 



Codeset identification (octet 1): 
Bits 


3 2 1 









codeset (initially active): 

3GPP TS 24.008 information elements 


1 


} 




to 

1 


} reserved 
} 




1 1 


codeset 5: 


information elements for national use 


1 1 

1 1 1 


codeset 6: 
codeset 7: 


information elements specific to the local networl< 
(either public or private) 
user-specific information elements 



10.5.4.4 Auxiliary states 

The purpose of the auxiUary states information element is to describe the current status of the auxiliary states of a call in 
the call control states "active" and "mobile originating modify". (See TSs 3GPP TS 24.083 [27] and 24.084 [28]) 

The auxiliary states information element is coded as shown in figure 10.5.87/3GPP TS 24.008, table 10.5.100/3GPP TS 
24.008 and table 10.5.101/3GPP TS 24.008. 

The auxiliary states is a type 4 information element with 3 octets length. 
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Auxiliary states lEI 
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/ states contents 


1 
ext 






spare 


hold aux. 
state 


MPTY aux. 
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octet 1 



octet 2 



octet 3 



Figure 10.5.87/3GPP TS 24.008 Auxiliary states information element 
Table 1 0.5.1 00/3GPP TS 24.008: Auxiliary states information element 



Hold auxiliary state (octet 3) 



Bits 






4 3 









idle 


Note1 


1 


hold request 


Note1 


1 


call held 


Note 1 


1 1 


retrieve request 


Note1 



Note 1 : These states are defined in Rec 3GPP TS 24.083 [27]. 
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Table 10.5.101/3GPP TS 24.008: Auxiliary states information element 



Multi party 


auxiliary state (octet 3) 




Bits 






2 1 









idle 


Note 2 


1 


IVIPTY request 


Note 2 


1 


call in MPTY 


Note 2 


1 1 


split request 


Note 2 


Note 2: 


These states are defined in Rec 3GPP TS 24.084 [28]. 



1 0.5.4.4a Backup bearer capability 

The purpose of the backup bearer capability IE is to indicate a requested service to a MS in case a complete description 
of the bearer service by a bearer capability IE is not available. The backup bearer capability information element is not 
subject to compatibility checking as described in annex B. 

The backup bearer capability IE is coded as shown in figure 10.5.87a/3GPP TS 24.008 and 
tables 10.5.101a/3GPP TS 24.008 to 10.5.101m/3GPP TS 24.008. 

The backup bearer capability is a type 4 information element with a minimum length of 3 octets and a maximum length 
of 15 octets. 
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Figure 10.5.87a/3GPP TS 24.008 Backup bearer capability information element 
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NOTE: The coding of the octets of the backup bearer capability IE is not conforming to the coding of the bearer 
capability IE in ITU Q.93 1 . 

Table 10.5.1 01 a/3GPP TS 24.008: Backup bearer capability information element 



Radio channel requirement (octet 3) 

In A/Gb mode and GERAN lu mode, i.e. not applicable for UTRAN lu mode data services. 

Bits 6 and 7 are spare bits. The sending side (i.e. the network) shall set bit 7 to value and bit 6 to 
value 1. 

Coding standard (octet 3) 

Bit 

5 

GSM standardized coding as described below 

1 reserved 

Transfer mode (octet 3) 

Bit 

4 

circuit mode 

1 packet mode 

Information transfer capability (octet 3) 

Bits 

321 

speech 

1 unrestricted digital information 

10 3.1 kHz audio, ex PLMN 

1 1 facsimile group 3 

1 1 Other ITC (See Octet 5a) 

1 1 1 reserved, to be used in the network. 

The meaning is: alternate speech/facsimile group 3 - starting with speech. 

All other values are reserved 
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Table 10.5.1 01 b/3GPP TS 24.008: Backup bearer capability information element 



Compression (octet 4) 

Bit 7 is spare and sliall be set to "0". 

Structure (octet 4) 

Bits 
65 

service data unit integrity 

1 1 unstructured 

All other values are reserved. 

Duplex mode (octet 4) 

Bit 

4 

half duplex 

1 full duplex 

Configuration (octet 4) 

Bit 

3 

point-to-point 

All other values are reserved. 

NIRR (octet 4) 

(Negotiation of Intermediate Rate Requested) 

In A/Gb mode and GERAN lu mode, i.e. not applicable for UTRAN lu modedata services. 

Bit 2 is spare and shall be set to "0". 

Establishment (octet 4) 

Bit 

1 

demand 

All other values are reserved 



Table 10.5.1 01 c/SGPP TS 24.008: Backup bearer capability information element 



Access identity (octet 5) 

Bits 

76 

octet identifier 

All other values are reserved 



Rate adaption (octet 5) 
Bits 



54 

00 

1 

1 

1 1 



no rate adaption 

V.110, I.460/X.30 rate adaptation 

ITU-T X.31 flag stuffing 

Other rate adaption (see octet 5a) 



Signalling access protocol (octet 5) 

Bits 
321 

1 1.440/450 

All other values are reserved. 
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Table 10.5.1 01 d/3GPP TS 24.008: Backup bearer capability information element 



Other lie (octet 5a) 

If the value "Other ITC" is not signalled in the field "ITC" then the contents of this field shall be 

ignored. 

Bit 
76 

restricted digital information 

All other values are reserved 



Other rate adaption (octet 5a) 

If the value " Other rate adaption" is not signalled in the field "Rate adaption" then the contents of 

this field shall be ignored. 

In UTRAN lu mode, PIAFS shall be considered. In A/Gb mode and GERAN lu mode, call shall be 

rejected if PIAFS requested. 



Bit 
54 

00 

1 

1 



V.120 

H.223 & H.245 

PIAFS 



All other values are reserved. 



Table 10.5.1 01 e/3GPP TS 24.008: Backup bearer capability information element 



Layer 1 identity (octet 6) 

Bits 

76 

1 octet identifier 

All other values are reserved 

User information layer 1 protocol (octet 6) 

Bits 

5432 

default layer 1 protocol 

All other values reserved. 

Synchronous/asynchronous (octet 6) 

Bit 

1 

synchronous 

1 asynchronous 
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Table 10.5.101f/3GPP TS 24.008: Backup bearer capability information element 



Number of Stop Bits (octet 6a) 

Bit 

7 

1 bit (Tliis value is also used in the case of synchronous mode) 

1 2 bits 

Negotiation (octet 6a) 

Bit 

6 

in-band negotiation not possible 

NOTE: See Rec. V.110 and X.30 

All other values are reserved 

Number of data bits excluding parity bit if present (octet 6a) 

Bit 

5 

7 bits 

1 8 bits (this value is also used in the case of bit oriented protocols) 

User rate (octet 6a) 

In A/Gb mode and GERAN lu mode only. 



Bits 
4321 

0000 
0001 
0010 
0011 
100 
0101 
0110 
111 



User rate unl<nown 

0.3 kbit/s Recommendation X.I and V.1 10 

1 .2 kbit/s Recommendation X.I and V.1 1 

2.4 kbit/s Recommendation X.I and V.1 10 

4.8 kbit/s Recommendation X.I and V.1 10 

9.6 kbit/s Recommendation X.I and V.1 10 

12.0 kbit/s transparent (non compliance with X.I and V.1 10) 

reserved: was allocated in earlier phases of the protocol. 



All other values are reserved. 

For facsimile group 3 calls the user rate indicates the first and maximum speed the mobile station 
is using. 
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Table 10.5.1 01 g/3GPP TS 24.008: Backup bearer capability information element 



Octet 6b for V.1 1 0/X.30 rate adaptation Intermediate rate (octet 6b) 

In A/Gb mode and GERAN lu mode only. 

If the value "User rate unknown" is signalled in the field "User rate" then the contents of this field 

shall be ignored. 



Bits 
76 
00 

1 

1 

1 1 



reserved 
reserved 
8 kbit/s 
16kbit/s 



Network independent clock (NIC) on transmission (Tx) (octet 6b) (See Rec. V.110 and X.30). 
In A/Gb mode and GERAN lu mode only. 



Bit 
5 

does not require to send data with network independent clock 

1 requires to send data with network independent clock 

Network independent clock (NIG) on reception (Rx) (octet 6b) (See Rec. V.1 1 and X.30) 
In A/Gb mode and GERAN lu mode only. 



Bit 
4 

cannot accept data with network independent clock (i.e. sender does not support this 
optional procedure) 

1 can accept data with network independent clock (i.e. sender does support this optional 
procedure) 

Parity information (octet 6b) 

Bits 

321 

000 odd 

1 even 

1 1 none 

1 forced to 
1 1 forced to 1 

All other values are reserved. 
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Table 10.5.101 h/3GPP TS 24.008: Backup bearer capability information element 



Connection element (octet 6c) 

Bit 

76 

00 

1 

1 

1 1 



transparent 
non transparent (RLP) 
both, transparent preferred 
both, non transparent preferred 



The networl< should use the 4 values depending on its capabilities to support the different modes. 

IVIodem type (octet 6c) 

Bits 

54321 

00000 

0000 1 

00010 

00011 

00100 

00101 

00110 

00111 

1000 



none 

V.21 (notel) 

V.22(note1) 

V.22 bis (notel) 

reserved: was allocated in earlier phases of the protocol 

V.26ter(note 1) 

V.32 

modem for undefined interface 

autobauding type 1 



All other values are reserved. 
Note 1 : In A/Gb mode and GERAN lu mode only. 



Table 10.5.101 i/3GPP TS 24.008: Backup bearer capability information element 



Other modem type (octet 6d) 

Bits 

76 

no other modem type specified in this field 

1 V.34 

All other values are reserved. 

Fixed network user rate (octet 6d) 

Bit 

54321 

00000 

0000 1 
00010 
00011 
00100 
0010 1 
00110 
00111 
1000 
1001 
1010 
1011 



Fixed network user rate not applicable/No meaning is associated 

with this value. 

9.8 kbit/s Recommendation X.I and V.1 10 

14.4kbit/s Recommendation X.I and V.1 10 

19.2 kbit/s Recommendation X.I and V.1 10 

28.8 kbit/s Recommendation X.I and V.1 10 

38.4 kbit/s Recommendation X.I and V.1 10 

48.0 kbit/s Recommendation X.I and V.IIO(synch) (note 1) 

56.0 kbit/s Recommendation X.I and V.I lO(synch) /bit transparent 

64.0 kbit/s bit transparent 

33.6 kbit/s bit transparent (note 2) 

32.0 kbit/s Recommendation 1.460 

31 .2 kbit/s Recommendation V.34 (note 2) 



The value 31 .2 kbit/s Recommendation V.34 shall be used only by the network to inform the MS 
about FNUR modification due to negotiation between the modems in a 3.1 kHz multimedia call. 

All other values are reserved. 

Note 1 : In A/Gb mode and GERAN lu mode only. 

Note 2: In UTRAN lu mode only 
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Table 10.5.101J/3GPP TS 24.008: Backup bearer capability information element 



Acceptable channel codings (octet 6e): 
Bits 4 to 7 are spare and shall be set to "0" 



Maximum number of traffic channels (octet 6e): 
Bits 1 to 3 are spare and shall be set to "0". 



Table 10.5.101 k/3GPP TS 24.008: Backup bearer capability information element 



UIMI, User initiated modification indication (octet 6f), 



765 

User initiated modification not allowed/applicable 

1 User initiated modification up to 1 TCH/F allowed/may be requested 

1 User initiated modification up to 2 TCH/F allowed/may be requested 

1 1 User initiated modification up to 3 TCH/F allowed/may be requested 

1 User initiated modification up to 4 TCH/F allowed/may be requested 

All other values shall be interpreted as "User initiated modification up to 4 TCH/F may be requested". 

User initiated modification indication is not applicable for transparent connection. 

Wanted air interface user rate (octet 6f): 
Bits 1 to 4 are spare and shall be set to "0". 



Table 10.5.101 1/3GPP TS 24.008: Backup bearer capability information element 



Layer 2 identity (octet 7) 

Bits 

76 

1 octet identifier 

All other values are reserved 

User information layer 2 protocol (octet 7) 

Bits 
54321 

110 reserved: was allocated in earlier phases of the protocol 

10 ISO 6429, codeset (DC1/DC3) 

10 1 reserved: was allocated but never used in earlier phases of the protocol 

10 10 videotex profile 1 

110 COPnoFICt (Character oriented Protocol with no Flow Control 

mechanism) 

110 1 reserved: was allocated In earlier phases of the protocol 

All other values are reserved. 
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Table 10.5.1 01 m/3GPP TS 24.008: Backup bearer capability information element 



Acceptable Channel Codings extended (octet 6g): 


Bits 3 to 7 are spare and shall be set to "0". 


Bits 2 and 1 are spare. 



10.5.4.4a.1 



Static conditions for the backup bearer capability IE contents 



If the information transfer capability field (octet 3) indicates "speech", octets 4, 5, 5a, 5b, 6, 6a, 6b, 6c, 6d, 6e, 6f, 6g 
and 7 shall not be included. 

If the information transfer capability field (octet 3) indicates a value different from "speech", octets 4 and 5shall be 
included, octets 6, 6a, 6b, 6c, 6d, 6e, 6f and 6g are optional. In case octet 6 is included, octets 6a, 6b, and 6c shall also 
be included. In case octet 6d is included, octets 6e, 6f and 6g may be included. If the information transfer capability 
field (octet 3) indicates "facsimile group 3" and octet 6c is included, the modem type field (octet 6c) shall indicate 
"none". 

If the information transfer capability field (octet 3) indicates "other ITC" or the rate adaption field (octet 5) indicates 
"other rate adaption", octet 5a shall be included. 

The modem type field (octet 6c) shall not indicate "autobauding type 1" unless the connection element field (octet 6c) 
indicates "non transparent". 

10.5.4.5 Bearer capability 

The purpose of the bearer capability information element is to describe a bearer service. The use of the bearer capability 
information element in relation to compatibility checking is described in annex B. 

The bearer capability information element is coded as shown in figure 10.5.88/3GPP TS 24.008 and 
tables 10.5.102/3GPP TS 24.008 to 10.5.115/3GPP TS 24.008. 

The bearer capability is a type 4 information element with a minimum length of 3 octets and a maximum length of 
16 octets. 
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Figure 10.5.88/3GPP TS 24.008 Bearer capability information element 

NOTE 1 : The coding of the octets of the bearer capabihty information element is not conforming to ITU Q.93 1 . 

An MS shall encode the Bearer Capability infomation element according to A/Gb mode call control requirements also if 
it is requesting for a service in lu mode, with the following exceptions: 

1 . A mobile station not supporting A/Gb mode and GERAN lu mode for the requested bearer service shall set 
the following parameters to the value "0": 

- Maximum number of traffic channels (octet 6e, bits 1-3) 

- Acceptable Channel coding(s) (octet 6e, bits 4, 5 and 7) 

2. Furthermore, a mobile station not supporting A/Gb mode and GERAN lu mode for the requested bearer 
service shall also set the following parameters to the value "0", if the respective octets have to be included in 
the bearer capability information element according to subclause 10.5.4.5.1 and 3GPP TS 27.001 [36]: 

- UIMI, User initiated modification indication (octet 6f, bits 5-7) 

- Acceptable Channel Codings extended (octet 6g, bits 5-7) 

For UTRAN lu mode the following parameters are irrelevant for specifying the radio access bearer, because multiple 
traffic channels (multislot) are not deployed, see 3GPP TS 23.034 [104]. However, the parameters if received, shall be 
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stored in the MSC, and used for handover to A/Gb or GERAN lu mode: 
Maximum number of traffic channels (octet 6e, bits 1-3) 
Acceptable Channel coding(s) (octet 6e, bits 4, 5 and 7) 
UIMI, User initiated modification indication (octet 6f, bits 5-7) 
Acceptable Channel Codings extended (octet 6g, bits 5-7) 

NOTE 2: The following parameters are relevant in UTRAN lu mode for non transparent data calls for deciding 
which RLP version to negotiate in order to avoid renegotiation of RLP version in case of inter-system 
handover from UTRAN lu mode to A/Gb or GERAN lu mode, see 3GPP TS 24.022 [9]: 

- Maximum number of traffic channels (octet 6e, bits 1-3) 

- Wanted air interface user rate (octet 6f, bits 1-4) 

UIMI, User initiated modification indication (octet 6f, bits 5-7). 

Table 1 0.5.1 02/3GPP TS 24.008: Bearer capability information element 



Radio channel requirement (octet 3), networl< to IVIS direction 

In A/Gb mode and GERAN lu mode, i.e. not applicable for UTRAN lu mode data services. 



Bits 6 and 7 are spare bits. The sending side (i.e. the network) shall set bit 7 to value and bit 6 to 
value 1. 

Radio channel requirement (octet 3) IVIS to network direction 

When information transfer capability (octet 3) indicates other values than speech: 

Bits 

76 

reserved 

1 full rate support only MS 

1 dual rate support IVIS/half rate preferred 
1 1 dual rate support IVIS/full rate preferred 

When information transfer capability (octet 3) indicates the value speech and no speech version 

indication is present in octet 3a etc.: 

Bits 

76 

reserved 

1 full rate support only MS/fullrate speech version 1 supported 

1 dual rate support MS/half rate speech version 1 preferred, full rate speech version 1 also 
supported 

1 1 dual rate support MS/fuU rate speech version 1 preferred, half rate speech version 1 also 
supported 

When information transfer capability (octet 3) indicates the value speech and speech version 

indication(s) is(are) present in octet 3a etc.: 

Bits 

76 

reserved 

1 the mobile station supports at least full rate speech version 1 but does not support half rate 

speech version 1. The complete voice codec preference is specified in octet(s) 3a etc. 

1 The mobile station supports at least full rate speech version 1 and half rate speech version 

1 . The mobile station has a greater preference for half rate speech version 1 than for full 
rate speech version 1. The complete voice codec preference is specified in octet(s) 3a etc. 

1 1 The mobile station supports at least full rate speech version 1 and half rate speech version 
1 . The mobile station has a greater preference for full rate speech version 1 than for half 
rate speech version 1. The complete voice codec preference is specified in octet(s) 3a etc. 



(continued...) 
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Table 1 0.5.1 02/3GPP TS 24.008: Bearer capability information element (continued) 



Coding standard (octet 3) 

Bit 

5 

GSIVI standardized coding as described below 

1 reserved 

Transfer mode (octet 3) 

Bit 

4 

circuit mode 

1 pacl<et mode 

Information transfer capability (octet 3) 

Bits 

321 

speech 

1 unrestricted digital information 

10 3.1 kHz audio, ex PLMN 

1 1 facsimile group 3 

1 1 Other ITC (See Octet 5a) 

1 1 1 reserved, to be used in the network. 

The meaning is: alternate speech/facsimile group 3 - starting with speech. 

All other values are reserved 
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Table 1 0.5.1 03/3GPP TS 24.008 Bearer capability information element 



Octet(s) 3a etc. MS to network direction 

Octet(s) 3a etc., bits 1 to 4 shall only be used to convey speech coding information belonging to a 

A/Gb mode or GERAN lu mode. When included for a UTRAN lu mode call establishment they 

shall be used for handover to A/Gb mode or GERAN lu mode. 

A mobile station supporting GTM text telephony, but not supporting A/Gb mode or GERAN lu 

mode shall encode octet 3a, bits 1 to 4 as "no speech version supported for GERAN". 

Coding 

Bit 

7 

octet used for extension of information transfer capability 

1 octet used for other extension of octet 3 

When information transfer capability (octet 3) indicates speech and coding (bit 7 in octet 3a etc.) is 
coded as 0, bits 1 through 6 are coded: 

GTM text telephony indication (octet 3a) 

Bit 

6 

GTM text telephony is not supported 

1 GTM text telephony is supported 

Bit 6 in octet(s) 3b etc. is spare. 

Bit 5 in octet(s) 3a etc. is spare. 

Speech version indication (octet(s) 3a etc.) 

Bits 

4321 

0000 

0010 

100 

110 

1000 

0001 

101 

111 

1011 

1111 



GSM full rate speech version 1 

GSM full rate speech version 2 

GSM full rate speech version 3 

GSM full rate speech version 4 

GSM full rate speech version 5 

GSM half rate speech version 1 

GSM half rate speech version 3 

GSM half rate speech version 4 

GSM half rate speech version 6 

no speech version supported for GERAN (note 1 ) 
All other values have the meaning "speech version tbd" and shall be ignored 
when received. 



(note 2) 

(note 2) 

(note 2) 

(note 2) 

(note 2) 

(note 2) 

(note 2) 

(note 2) 

(note 2) 



NOTE 1 : This value shall only be used by an MS supporting CTM text telephony, but not 
supporting A/Gb or GERAN lu mode. 

NOTE 2: As defined in 3GPP TS 26.103 [83] and 3GPP TS 48.008 [85]. 

If octet 3 is extended with speech version indication(s) (octets 3a etc.), all speech versions 
supported shall be indicated and be included in order of preference (the first octet (3a) has the 
highest preference and so on). 

If information transfer capability (octet 3) indicates speech and coding (bit 7 in octet 3a etc.) is 
coded as 1 , or the information transfer capability does not indicate speech, then the extension 
octet shall be ignored. 

Octet(s) 3a etc. network to MS direction 

The octet(s) 3a etc. shall be ignored by the MS. 
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Table 1 0.5.1 04/3GPP TS 24.008: Bearer capability information element 



Compression (octet 4), network to MS direction: 

Bit 

7 

data compression not possible 

1 data compression possible 

Compression (octet 4), MS to network direction: 

Bit 

7 

data compression not allowed 

1 data compression allowed 

Structure (octet 4) 

Bits 
65 

service data unit integrity 

1 1 unstructured 

All other values are reserved. 

Duplex mode (octet 4) 

Bit 

4 

half duplex 

1 full duplex 

Configuration (octet 4) 

Bit 

3 

point-to-point 

All other values are reserved. 

NIRR (octet 4) 

(Negotiation of Intermediate Rate Requested) 

In A/Gb mode and GERAN lu mode, i.e. not applicable for UTRAN lu mode data services. 

Bit 
2 

No meaning is associated with this value. 

1 Data up to and including 4.8 kb/s, full rate, non-transparent, 6 kb/s radio interface rate is 
requested. 

Establishment (octet 4) 

Bit 

1 

demand 

All other values are reserved 
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Table 1 0.5.1 05/3GPP TS 24.008: Bearer capability information element 



Access identity (octet 5) 

Bits 

76 

octet identifier 

All other values are reserved 



Rate adaption (octet 5) 

Bits 

54 

no rate adaption 

1 V.110, I.460/X.30 rate adaptation 

1 ITU-T X.31 flag stuffing 

1 1 Other rate adaption (see octet 5a) 

Signalling access protocol (octet 5) 

Bits 
321 

1 1.440/450 

1 reserved: was allocated in earlier phases of the protocol 

1 1 reserved: was allocated in earlier phases of the protocol 

1 reserved: was allocated in earlier phases of the protocol. 
1 1 reserved: was allocated in earlier phases of the protocol 
1 1 reserved: was allocated in earlier phases of the protocol 

All other values are reserved. 



Table 1 0.5.1 06/3GPP TS 24.008: Bearer capability information element 



Other ITC (octet 5a) 

If the value "Other ITC" is not signalled in the field "ITC" then the contents of this field shall be 

ignored. 

Bit 
76 

restricted digital information 

All other values are reserved 



Other rate adaption (octet 5a) 

If the value " Other rate adaption" is not signalled in the field "Rate adaption" then the contents of 

this field shall be ignored. 

In UTRAN lu mode, PIAFS shall be considered. In A/Gb mode and GERAN lu mode, call shall be 

rejected if PIAFS requested. 



Bit 
54 
V.I 20 

1 H.223 & H.245 

1 PIAFS 

All other values are reserved. 
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Table 1 0.5.1 07/3GPP TS 24.008: Bearer capability information element 



Rate adaption header/no header (octet 5b) 

Bit 
7 

Rate adaption header not included 

1 Rate adaption header included 

IVIultiple frame establishment support in data linl< (octet 5b) 

Bit 
6 

IVIultiple frame establishment not supported, only Ul frames allowed 

1 IVIultiple frame establishment supported 

IVIode of operation (octet 5b) 

Bit 
5 

Bit transparent mode of operation 

1 Protocol sensitive mode of operation 

Logical link identifier negotiation (octet 5b) 

Bit 
4 

Default, LLI=256 only 

1 Full protocol negotiation, (note: A connection over which protocol negotiation will 
be executed is indicated in bit 2 of octet 5b) 

Assignor/Assignee (octet 5b) 

Bit 
3 

Message originator is "default assignee" 

1 IVIessage originator is "assignor only" 

In band/Out of band negotiation (octet 5b) 

Bit 
2 

Negotiation is done in-band using logical link zero 

1 Negotiation is done with USER INFORIVIATION messages on a temporary 
signalling connection 

Bit 1 is spare and set to the value "0" 
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Table 1 0.5.1 08/3GPP TS 24.008: Bearer capability information element 



Layer 1 identity (octet 6) 

Bits 

76 

1 octet identifier 

All otiier values are reserved 

User information layer 1 protocol (octet 6) 

Bits 

5432 

default layer 1 protocol 

All other values reserved. 

Synchronous/asynchronous (octet 6) 

Bit 

1 

synchronous 

1 asynchronous 



Table 1 0.5.1 09/3GPP TS 24.008: Bearer capability information element 



Number of Stop Bits (octet 6a) 

Bit 

7 

1 bit (This value is also used in the case of synchronous mode) 

1 2 bits 

Negotiation (octet 6a) 

Bit 

6 

in-band negotiation not possible 

NOTE: See Rec. V.110 and X.30 

All other values are reserved 

Number of data bits excluding parity bit if present (octet 6a) 

Bit 

5 

7 bits 

1 8 bits (this value is also used in the case of bit oriented protocols) 

User rate (octet 6a) 

In A/Gb mode and GERAN lu mode only. 



Bits 
4321 

0001 
0010 
0011 
100 
101 
110 
111 



0.3 kbit/s Recommendation X.I and V.1 10 

1 .2 kbit/s Recommendation X.I and V.1 1 

2.4 kbit/s Recommendation X.I and V.1 10 

4.8 kbit/s Recommendation X.I and V.1 10 

9.6 kbit/s Recommendation X.I and V.1 10 

12.0 kbit/s transparent (non compliance with X.1 and V.1 10) 

reserved: was allocated in earlier phases of the protocol. 



All other values are reserved. 

For facsimile group 3 calls the user rate indicates the first and maximum speed the mobile station 
is using. 
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Table 1 0.5.11 0/3GPP TS 24.008: Bearer capability information element 



Octet 6b for V.1 1 0/X.30 rate adaptation Intermediate rate (octet 6b) 
In A/Gb mode and GERAN lu mode only. 



Bits 
76 

reserved 

1 reserved 

1 8 kbit/s 
1116 kbit/s 

Network independent clock (NIC) on transmission (Tx) (octet 6b) (See Rec. V.1 10 and X.30). 
In A/Gb mode and GERAN lu mode only. 



Bit 
5 

does not require to send data with network independent clock 

1 requires to send data witli network independent clock 

Network independent clock (NIG) on reception (Rx) (octet 6b) (See Rec. V.1 1 and X.30) 
In A/Gb mode and GERAN lu mode only. 



Bit 
4 

cannot accept data with network independent clock (i.e. sender does not support this 
optional procedure) 

1 can accept data with network independent clock (i.e. sender does support this optional 
procedure) 

Parity information (octet 6b) 

Bits 

321 

000 odd 

1 even 

1 1 none 

1 forced to 
1 1 forced to 1 

All other values are reserved. 
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Table 10.5.111/3GPP TS 24.008: Bearer capability information element 



Connection element (octet 6c) 

Bit 

76 

transparent 

1 non transparent (RLP) 

1 both, transparent preferred 

1 1 both, non transparent preferred 

The requesting end (e.g. the one sending the SETUP message) should use the 4 values 
depending on its capabilities to support the different modes. The answering party shall only use 
the codings 00 or 01 , based on its own capabilities and the proposed choice if any. If both MS and 
network support both transparent and non transparent, priority should be given to the MS 
preference. 

Modem type (octet 6c) 

Bits 

54321 

00000 

0000 1 

00010 

00011 

00100 

00101 

00110 

00111 

1000 



none 

V.21 (note1) 

V.22(note1) 

V.22 bis (note 1) 

reserved: was allocated in earlier phases of the protocol 

V.26ter(note 1) 

V.32 

modem for undefined interface 

autobauding type 1 



All other values are reserved. 
Note 1 : In A/Gb mode and GERAN lu mode only. 
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Table 1 0.5.11 2/3GPP TS 24.008: Bearer capability information element 



Other modem type (octet 6d) 

Bits 

76 

no other modem type specified in this field 

1 V.34 

All other values are reserved. 

Fixed network user rate (octet 6d) 

Bit 

54321 

Fixed network user rate not applicable/No meaning is associated 

with this value. 
1 9.6 kbit/s Recommendation X.1 and V.11 

000 10 14.4 kbit/s Recommendation X.I and V.1 10 

0001 1 19.2 kbit/s Recommendation X.I and V.1 10 
10 28.8 kbit/s Recommendation X.I and V.1 10 
10 1 38.4 kbit/s Recommendation X.I and V.1 10 

110 48.0 kbit/s Recommendation X.I and V.IIO(synch) (note 1) 

111 56.0 kbit/s Recommendation X.I and V.I lO(synch) /bit transparent 

10 64.0 kbit/s bit transparent 

10 1 33.6 kbit/s bit transparent (note 2) 

10 10 32.0 kbit/s Recommendation 1.460 

10 11 31 .2 kbit/s Recommendation V.34 (note 2) 

The value 31 .2 kbit/s Recommendation V.34 shall be used only by the network to inform the MS 
about FNUR modification due to negotiation between the modems in a 3.1 kHz multimedia call. 

All other values are reserved. 

Note 1 : In A/Gb mode and GERAN lu mode only. 

Note 2: In UTRAN lu mode only 
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Table 1 0.5.11 3/3GPP TS 24.008: Bearer capability information element 



Acceptable channel codings (octet 6e), mobile station to network direction: 



Bit 
7 

TCH/F1 4.4 not acceptable 

1 TCH/F1 4.4 acceptable 

Bit 

6 

Spare 

Bit 
5 

TCH/F9.6 not acceptable 

1 TCH/F9.6 acceptable 

Bit 
4 

TCH/F4.8 not acceptable 

1 TCH/F4.8 acceptable 

Acceptable channel codings (octet 6e), network to MS direction: 
Bits 4 to 7 are spare and shall be set to "0". 



l\/laximum number of traffic channels (octet 6e), MS to network direction: 



Bits 
321 

000 
001 



1 TCH 
2TCH 



10 3 TCH 
Oil 4 TCH 



1 00 
1 01 



5 TCH 

6 TCH 



110 7 TCH 
1 1 1 8 TCH 

IVIaximum number of traffic channels (octet 6e), network to MS direction: 
Bits 1 to 3 are spare and shall be set to "0". 
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Table 1 0.5.11 4/3GPP TS 24.008: Bearer capability information element 



UIMI, User initiated modification indication (octet 6f), 



765 

000 
001 
01 

1 1 

1 00 



User initiated modification not allowed/required/applicable 
User initiated modification up to 1 TCH/F allowed/may be requested 
User initiated modification up to 2 TCH/F allowed/may be requested 
User initiated modification up to 3 TCH/F allowed/may be requested 
User initiated modification up to 4 TCH/F allowed/may be requested 



All other values shall be interpreted as "User initiated modification up to 4 TCH/F may be requested" 

User initiated modification indication is not applicable for transparent connection. 

Wanted air interface user rate (octet 6f), MS to network direction: 

Bits 

4321 

OAir interface user rate not applicable/No meaning associated with this value 

1 9.6 kbit/s 

00 10 14.4 kbit/s 

00 11 19.2 kbit/s 

10 1 28.8 kbit/s 

110 38.4 kbit/s 

111 43.2 kbit/s 

10 57.6 kbit/s 

10 1 interpreted by the network as 38.4 kbit/s in this version of the protocol 

10 10 interpreted by the network as 38.4 kbit/s in this version of the protocol 

10 11 interpreted by the network as 38.4 kbit/s in this version of the protocol 

110 interpreted by the network as 38.4 kbit/s in this version of the protocol 

All other values are reserved. 

Wanted air interface user rate (octet 6f), network to MS direction: 
Bits 1 to 4 are spare and shall be set to "0". 
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Table 1 0.5.11 5/3GPP TS 24.008: Bearer capability information element 



Layer 2 identity (octet 7) 

Bits 

76 

1 octet identifier 

All other values are reserved 

User information layer 2 protocol (octet 7) 

Bits 
54321 

110 reserved: was allocated in earlier phases of the protocol 

10 ISO 6429, codeset (DC1/DC3) 

10 1 reserved: was allocated but never used in earlier phases of the protocol 

10 10 videotex profile 1 

110 COPnoFICt (Character oriented Protocol with no Flow Control 

mechanism) 

110 1 reserved: was allocated in earlier phases of the protocol 

All other values are reserved. 



Table 10.5.1 15a/3GPP TS 24.008: Bearer capability information element 



Acceptable Channel Codings extended (octet 6g) mobile station to network direction: 



Bit 
7 

TCH/F28.8 not acceptable 

1 TCH/F28.8 acceptable 

Bit 
6 

TCH/F32.0 not acceptable 

1 TCH/F32.0 acceptable 

Bit 
5 

TCH/F43.2 not acceptable 

1 TCH/F43.2 acceptable 

Channel Coding Asymmetry Indication 



Bits 
43 
00 
1 

1 

1 1 



Channel coding symmetry preferred 

Downlink biased channel coding asymmetry is preferred 

Uplink biased channel coding asymmetry is preferred 

Unused, if received it shall be interpreted as "Channel coding symmetry preferred" 



EDGE Channel Codings (octet 6g), network to IVIS direction: 

Bits 3 to 7 are spare and shall be set to "0". 
Bits 2 and 1 are spare. 
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10.5.4.5.1 



Static conditions for the bearer capability IE contents 



If the information transfer capability field (octet 3) indicates "speech", octets 4, 5, 5a, 5b, 6, 6a, 6b, 6c, 6d, 6e, 6f, 6g 
and 7 shall not be included. 

If the information transfer capability field (octet 3) indicates "speech", octet 3a etc. shall be included only if the mobile 
station supports CTM text telephony or if it supports at least one speech version for GERAN other than: 

GSM full rate speech version 1 ; or 

GSM half rate speech version 1. 

If the information transfer capability field (octet 3) indicates a value different from "speech", octets 4, 5, 6, 6a, 6b, and 
6c shall be included, octets 6d, 6e, 6f and 6g are optional. In the network to MS direction in case octet 6d is included, 
octets 6e, 6f and 6g may be included. In the MS to network direction in case octet 6d is included octet 6e shall also be 
included and 6f and 6g may be included. 

If the information transfer capability field (octet 3) indicates "facsimile group 3", the modem type field (octet 6c) shall 
indicate "none". 

If the information transfer capability field (octet 3) indicates "other ITC" or the rate adaption field (octet 5) indicates 
"other rate adaption", octet 5a shall be included. 

If the rate adaption field (octet 5) indicates "other rate adaption" and the other rate adaption field (octet 5a) indicates 
"V.120", octet 5b shall be included. 

The modem type field (octet 6c) shall not indicate "autobauding type 1 " unless the connection element field (octet 6c) 
indicates "non transparent". 

1 0.5.4.5a Call Control Capabilities 

The purpose of the Call Control Capabilities information element is to identify the call control capabilities of the mobile 
station. 

The Call Control Capabilities information element is coded as shown in figure 10.5.89/3GPP TS 24.008 and 
table 10.5.116/3GPP TS 24.008. 

The Call Control Capabilities is a type 4 information element with a length of 4 octets. 



8 7 6 5 


4 


3 


2 


1 


1 Call Control Capabilities lEI 


Length of Call Control Capabilities contents 


IVIaximum number of supported 
bearers 


MCAT 


ENICM 


PCP 


DTMF 



spare 


Maximum number of 
speech bearers 



octet 1 
octet 2 
octets 



octet 4 



Figure 10.5.89/3GPP TS 24.008 Call Control Capabilities information element 
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Table 1 0.5.11 6/3GPP TS 24.008: Call Control Capabilities 



DTMF(octet3, bit 1) 

This value is reserved for earlier versions of the protocol. 

1 This value indicates that the mobile station supports DTMF as specified 
in subclause 5.5.7 of the present document. 

PCP (octet 3, bit 2) 

This value indicates that the mobile station does not support the 
Prolonged Clearing Procedure 

1 This value indicates that the mobile station supports the Prolonged 
Clearing Procedure. 

ENICM (octet 3, bit 3) 

This value indicates that the mobile station does not support the 
Enhanced Network-initiated In-Call Modification procedure. 

1 This value indicates that the mobile station supports the Enhanced 
Network-initiated In-Call Modification procedure as specified in 
subclause 5.3.4.3 of the present document. 

MCAT (octet 3, bit 4) 

This value indicates that the mobile station does not support Multimedia 
CAT. 

1 This value indicates that the mobile station supports Multimedia CAT 
during the alerting phase of a mobile originated multimedia call 
establishment as specified in subclause 5.3.6.4 of the present document. 

Maximum number of supported bearers (octet 3, bit 5 to bit 8) 
1 bearer supported 

All values are interpreted as the binary representation of the number of bearers 
supported. 

Bit 5 of octet 3 is the least significant bit and bit 8 of octet 3 is the most significant bit. 

Maximum number of speech bearers (octet 4, bit 1 to bit 4) 

All values are interpreted as the binary representation of the number of bearers 
supported. 

Bit 1 of octet 4 is the least significant bit and bit 4 of octet 4 is the most significant bit. 

Note: In this version of the protocol, the MS should not indicate more than one 
speech bearer. 



10.5.4.6 Call state 

The purpose of the call state information element is to describe the current status of a call, (see subclause 5.1). 

The call state information element is coded as shown in figure 10.5.90/3GPP TS 24.008 and 
table 10.5.117/3GPP TS 24.008. 

The call state is a type 3 information element with 2 octets length. 



8 7 


6 


5 4 3 2 


1 


1 call state lEI 


coding 
standard 


call state value (coded in binary) 



octet 1 



octet 2 



Figure 10.5.90/3GPP TS 24.008 Call state information element 
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Table 1 0.5.11 7/3GPP TS 24.008: Call state information element 



Coding standard (octet 2) 
Bits 




8 7 








standardized coding as described in ITU-T Rec. Q.931 


1 






reserved for other international standards 


1 






national standard 




1 1 






standard defined for the GSM PLMNS < 


as described below 


Coding standards other than "1 1 - Standard defined for the GSIVI PLMNS" shall not be 


used if the call state 


can be represented with the GSM standardized coding. 


The mobile station or network need not support any other coding standard than 


"1 1 - 


standard defined for the GSIVI PLMNS". 




If a call state IE indicating a coding standard not supported by the receiver is received, 


call state 


'active' 


shall be assumed. 




Call St 
Bits 
6 5 


ate value (octet 2) 




4 


3 


2 


1 





















UO-null 


NO -null 











1 





U0.1- MM connection pending 


N0.1- MM connection pending 


1 








1 





U0.2- CC prompt present 


N0.2- CC connection pending 


1 








1 


1 


U0.3- Wait for network 
information 


NO. 3- Network answer pending 


1 





1 








U0.4- CC-Establishment 
present 


NO. 4- CC-Establishment 
present 


1 





1 





1 


U0.5- CC-Establishment 
confirmed 


N0.5- CC-Establishment 
confirmed 


1 





1 


1 





U0.6- Recall present 


NO. 6- Recall present 














1 


U1 - call initiated 


N1 - call initiated 











1 


1 


U3 - mobile originating call 
proceeding 


N3 - mobile originating call 
proceeding 








1 








U4 - call delivered 


N4 - call delivered 








1 


1 





U6 - call present 


N6 - call present 








1 


1 


1 


U7 - call received 


N7 - call received 
















U8 - connect request 


N8 - connect request 













1 


U9 - mobile terminating call 
confirmed 


N9 - mobile terminating call 
confirmed 










1 





U 10- active 


N10- active 










1 


1 


U1 1 - disconnect request 









1 








U12- disconnect indication 


N12-disconnect indication 


1 








1 


1 


U19- release request 


N19- release request 


1 







1 





U26- mobile originating modify 


N26- mobile originating modify 


1 







1 


1 


U27- mobile terminating modify 


N27- mobile terminating modify 


1 




1 










N28- connect indication 



10.5.4.7 Called party BCD number 

The purpose of the called party BCD number information element is to identify the called party. 

The called party BCD number information element is coded as shown in figure 10.5.91/3GPP TS 24.008 and 
table 10.5.118/3GPP TS 24.008. 

The called party BCD number is a type 4 information element with a minimum length of 3 octets and a maximum 
length of 43 octets. For PCS 1900 the maximum length is 19 octets. 
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8 


7 6 5 


4 3 2 1 


1 Called party BCD number lEI 


Length of called party BCD number contents 


1 
ext 


type of 
number 


Numbering plan 
identification 


Number digit 2 


Number digit 1 


Number digit 4 


Number digit 3 


2) 





octet 1 
octet 2 
octet 3 
octet 4* 
octet 5* 



Figure 10.5.91/3GPP TS 24.008 Called party BCD number information element 

NOTE 1 : The number digit(s) in octet 4 precedes the digit(s) in octet 5 etc. The number digit which would be 
entered first is located in octet 4, bits 1 to 4. 

NOTE 2: If the called party BCD number contains an odd number of digits, bits 5 to 8 of the last octet shall be 
filled with an end mark coded as "1111". 

Since the information element must contain the complete called party BCD number there is no need for an additional 
complete indication. 

Table 1 0.5.11 8/3GPP TS 24.008: Called party BCD number 



Type of PL 


mber (octet 3) (Note 1 ) 


Bits 




7 6 5 







unknown (Note 2) 


1 


international number (Note 3, Note 5) 


1 


national number (Note 3) 


1 1 


network specific number (Note 4) 


1 


dedicated access, short code 


1 1 


reserved 


1 1 


reserved 


1 1 1 


reserved for extension 



NOTE 1: For the definition of "number" see ITU-T Recommendation 1.330 and 3GPP TS 23.003 [10]. 

NOTE 2: The type of number "unknown" is used when the user or the network has no knowledge of the type of 

number, e.g. international number, national number, etc. In this case the number digits field is organized 
according to the network dialling plan, e.g. prefix or escape digits might be present. 

NOTE 3: Prefix or escape digits shall not be included. 

NOTE 4: The type of number "network specific number" is used to indicate administration/service number specific 
to the serving network, e.g. used to access an operator. 

NOTE 5: The international format shall be accepted by the MSC when the call is destined to a destination in the 
same country as the MSC. 
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Table 1 0.5.11 8/3GPP TS 24.008: Called party BCD number (continued) 



Numbering p 


an identification (octet 3) 


Number plan 


(applies for type of number = 000, 001 , 01 and 1 00) 


Bits 




4 3 2 1 







unknown 


1 


ISDN/telephony numbering plan (Rec. E.164/E.163) 


11 


data numbering plan (Recommendation X.I 21) 


10 


telex numbering plan (Recommendation F.69) 


10 


national numbering plan 


10 1 


private numbering plan 


10 11 


reserved for CIS (see 3GPP TS 44.056 [91]) 


1111 


reserved for extension 


All other values are reserved. 



When an MS is the recipient of number information from the network, any incompatibility between the number 
digits and the number plan identification shall be ignored and a STATUS message shall not be sent to the 
network. 

In the case of numbering plan "unknown", the number digits field is organized according to the network dialling 
plan; e.g. prefix or escape digits might be present. 



Table 10.5.1 18/3GPP TS 24.008: Called party BCD number (continued) 



Number digits (octets 4, 


etc.) 




Bits 










Number digit value 


4 3 


2 


1 


or 






8 7 


6 


5 






























1 






1 





1 









2 





1 


1 






3 


1 












4 


1 





1 






5 


1 


1 









6 


1 


1 


1 






7 


1 












8 


1 





1 






9 


1 


1 









* 


1 


1 


1 






# 


1 1 












a 


1 1 





1 






b 


1 1 


1 









c 


1 1 


1 


1 






used as an endmark in the case of an odd number of 
number digits 



1 0.5.4.8 Called party subaddress 

The purpose of the Called party subaddress is to identify the subaddress of the called party of a call. For the definition 
of a subaddress see Rec. ITU-T 1.330. 

The Called party subaddress information element is coded as shown in figure 10.5.92/3GPP TS 24.008 and 
Table 10.5.119/3GPP TS 24.008. 

The called party subaddress is a type 4 information element with a minimum length of 2 octets and a maximum length 
of 23 octets. 
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Called party Subaddress lEI 


octet 1 


Length of called party subaddress contents 


octet 2 


1 
ext 


type of 
subaddress 


odd/ev 
Indica 



spare 





octet 3* 


Subaddress information 


octet 4* 
etc. 



Figure 10.5.92/3GPP TS 24.008 Called party subaddress 
Table 1 0.5.11 9/3GPP TS 24.008: Called party subaddress 



Type of subaddress (octet 3) 



Bits 

7 6 5 



1 



NSAP (X.213/ISO 8348 AD2) 
User specified 



All other values are reserved 

Odd/even indicator (octet 3) 

Bit 

4 

even number of address signals 

1 odd number of address signals 

NOTE 1 : The odd/even indicator is used when the type of subaddress is "user 
specified" and the coding is BCD. 

Subaddress information (octet 4, etc..) 

The NSAP X.213/IS08348AD2 address shall be formatted as specified by octet 4 
which contains the Authority and Format Identifier (API). The encoding is made 
according to the "preferred binary encoding" as defined in X.21 3/IS08348AD2. For the 
definition of this type of subaddress, see Rec. ITU-T 1.334. 

A coding example is given in ANNEX A. 

For User-specific subaddress, this field is encoded according to the user specification, 
subject to a maximum length of 20 octets. 

NOTE 2: It is recommended that users apply NSAP subaddress type since this 

subaddress type allows the use of decimal, binary and IA5 characters in a 
standardised manner. 



1 0.5.4.9 Calling party BCD number 

The purpose of the calhng party BCD number information element is to identify the origin of a call. 

The calling party BCD number information element is coded as shown in figure 10.5.93/3GPP TS 24.008 and 
table 10.5.120/3GPP TS 24.008. 

The calling party BCD number is a type 4 information element. In the network to mobile station direction it has a 
minimum length of 3 octets and a maximum length of 14 octets. (This information element is not used in the mobile 
station to network direction.). 
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Calling party BCD number lEI 


octet 1 


Length of calling party BCD number contents 


octet 2 


0/1 
ext 


type of 
number 


Numbering plan 
identification 


octet 3 


1 
ext 


presentat. 
indicator 



spare 


screening 
indicator 


octet 3a 


Number digit 2 


Number digit 1 


octet 4* 


Number digit 4 


Number digit 3 


octet 5* 









Figure 10.5.93/3GPP TS 24.008 Calling party BCD number information element 

The contents of octets 3, 4, etc. are coded as shown in table 10.5.118. The coding of octet 3a is defined in table 10.5.120 
below. 

If the calling party BCD number contains an odd number of digits, bits 5 to 8 of the last octet shall be filled with an end 
mark coded as "1111". 



Table 1 0.5.1 20/3GPP TS 24.008: Calling party BCD number 



Presentation indicator (octet 3a) 

Bits 

7 6 

Presentation allowed 

1 Presentation restricted 

1 Number not available due to interworking 
1 1 Reserved 

If octet 3a is omitted the value "00 - Presentation allowed" is assumed. 

Screening indicator (octet 3a) 



Bits 
2 1 


1 

1 

1 1 



User-provided, not screened 
User-provided, verified and passed 
User-provided, verified and failed 
Network provided 



If octet 3a is omitted the value "0 - User provided, not screened" is assumed. 



1 0.5.4.1 Calling party subaddress 

The purpose of the Calling party subaddress is to identify a subaddress associated with the origin of a call. For the 
definition of a subaddress see Rec. ITU-T 1.330. 

The Calling party subaddress information element is coded as shown in figure 10.5.94/3GPP TS 24.008 and 
table 10.5.121/3GPP TS 24.008. 

The calling party subaddress is a type 4 information element with a minimum length of 2 octets and a maximum length 
of 23 octets. 
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8 


7 6 5 


4 


3 2 


1 


Calling party Subaddress lEI 


Length of calling party subaddress contents 


1 
ext 


type of 
subaddress 


odd/ev 
Indica 








Subaddress information 



octet 1 

octet 2 

octet 3* 

octet 4* 

etc. 

Figure 10.5.94/3GPP TS 24.008 Calling party subaddress 



Table 10.5.121/3GPP TS 24.008: Calling party subaddress 



Type of subaddress (octet 3) 

Bits 

7 6 5 

NSAP(X.213/IS0 8348AD2) 

1 User specified 
All other values are reserved 

Odd/even indicator (octet 3) 

Bit 

4 

even number of address signals 

1 odd number of address signals 

The odd/even indicator is used when the type of subaddress is "user specified" and the 
coding is BCD 

Subaddress information (octet 4, etc..) 

The NSAP X.213/IS08348AD2 address shall be formatted as specified by octet 4 
which contains the Authority and Format Identifier (API). The encoding is made 
according to the "preferred binary encoding" as defined in X.21 3/IS08348AD2. For the 
definition of this type of this type of subaddress, see Rec. ITU-T 1.332. 

A coding example is given in annex A. 

For User-specific subaddress, this field is encoded according to the user specification, 
subject to a maximum length of 20 octets. 

NOTE: It is recommended that users apply NSAP subad dress type since this 

subaddress type allows the use of decimal, binary and IA5 characters in a 
standardised manner. 



10.5.4.11 Cause 

The purpose of the cause information element is to describe the reason for generating certain messages, to provide 
diagnostic information in the event of procedural errors and to indicate the location of the cause originator. 

The cause information element is coded as shown in figure 10.5.95/3GPP TS 24.008 and tables 10.5.122 and 
10.5.123/3GPPTS 24.008. 

The cause is a type 4 information element with a minimum length of 4 octets and a maximum length of 32 octets. 

The cause information element may be repeated in a message. 
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8 


7 6 


5 


4 3 2 


1 


Cause lEI 


Length of cause contents 


0/1 
ext 


coding 
standard 



spare 


location 


1 
ext 


recommendation 


1 
ext 


cause value 


diagnostic{s) if any 



octet 1 
octet 2 
octet 3 
octet 3a* 
octet 4 
octet 5* 
octet N* 

Figure 10.5.95/3GPP TS 24.008 Cause information element 
If the default value applies for the recommendation field, octet 3a shall be omitted. 

Table 1 0.5.1 22/3GPP TS 24.008: Cause information element 



Coding standard (octet 3) 
Bits 
7 6 


1 

1 

1 1 



Coding as specified in ITU-T Rec. Q.931 

Reserved for other international standards 

National standard 

Standard defined for the GSM PLMNs as described below and in table 

10.5.123/3GPPTS 24.008 



Coding standards other than "1 1 - Standard defined for the GSM PLMNS" shall not be 
used if the cause can be represented with the GSM standardized coding. 

The mobile station or network need not support any other coding standard than "1 1 - 
Standard defined for the GSM PLMNS". 

If a cause IE indicating a coding standard not supported by the receiver is received, 
cause "interworking, unspecified" shall be assumed. 

Location (octet 3) 

Bits 

4 3 2 1 

user 

1 private network serving the local user 

10 public network serving the local user 

11 transit network 

10 public network serving the remote user 

10 1 private network serving the remote user 

111 international network 

10 10 network beyond interworking point 

All other values are reserved. 

Recommendation (octet 3a) 

Octet 3a shall not be included If the coding standard is coded as "1 1 - Standard 

defined for GSM PLMNS". 

If the coding standard is different from "1 1 - Standard defined for GSM PLMNS", the 
coding of octet 3a, if included, and octets 4 to N is according to that coding standard. 
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Table 1 0.5.1 22/3GPP TS 24.008: Cause information element (continued) 



Cause value (octet 4) 

The cause value is divided in two fields: a class (bits 5 through 7) and a value within 
the class (bits 1 through 4). 

The class indicates the general nature of the event. 



Class (000) 
Class (001) 
Class (010) 
Class (Oil) 
Class (100) 
Class (101) 
Class (110) 
Class (111) 



normal event 

normal event 

resource unavailable 

service or option not available 

service or option not implemented 

invalid message (e.g. parameter out of range) 

protocol error (e.g. unknown message) 

interworking 



The cause values are listed in Table 1 0.5.1 23/3GPP TS 24.008 below and defined in 
Annex H. 

Diagnostic(s) (octet 5) 

Diagnostic information is not available for every cause, see Table 10.5.123/3GPP TS 

24.008 below. 

When available, the diagnostic(s) is coded in the same way as the corresponding 
information element in clause 10. 

The inclusion of diagnostic(s) is optional. 
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Table 1 0.5.1 23/3GPP TS 24.008: Cause information element values 



Cause value 




Cause 


Cause 


Diag- 


Remarks 


Class 




Value 




num. 




nostic 




7 6 5 


4 


3 2 


1 





















1. 


Unassigned (unallocated) number 


Note 9 










1 




3. 


No route to destination 


Note 9 










1 1 





6. 


Channel unacceptable 


- 







1 








8. 


Operator determined barring 


- 




1 











16. 


Normal call clearing 


Note 9 




1 










17. 


User busy 


Note 1 




1 





1 





18. 


No user responding 


- 




1 





1 




19. 


User alerting, no answer 


- 




1 





1 




21. 


Gall rejected 


Note 9 - user supplied 
diagnostic (note 4) 


1 





1 1 





22. 


Number changed 


New destination(note 5) 


1 


1 








24. 


Call rejected due to feature at the 
destination 


- 




1 


1 







25. 


Pre-emption 






1 


1 


1 





26. 


Non selected user clearing 


- 




1 


1 


1 




27. 


Destination out of order 


- 




1 


1 


1 





28. 


Invalid number format (incomplete 
number) 


- 




1 


1 


1 




29. 


Facility rejected 


Note 1 




1 


1 


1 1 





30. 


Response to STATUS ENQUIRY 


- 




1 


1 


1 1 




31. 


Normal, unspecified 


- 




1 





1 





34. 


No circuit/channel available 


Motel 




1 





1 1 





38. 


Network out of order 


- 




1 


1 







41. 


Temporary failure 


- 




1 


1 


1 





42. 


Switching equipment congestion 


- 




1 


1 


1 




43. 


Access information discarded 


Discarded information 
element identifiers 
(note 6) 


1 


1 


1 





44. 


requested circuit/channel not available 


- 




1 


1 


1 1 




47. 


Resources unavailable, unspecified 


- 




1 1 










49. 


Quality of service unavailable 


Note 9 




1 1 





1 





50. 


Requested facility not subscribed 


Note 1 




1 1 





1 1 




55. 


Incoming calls barred within the CUG 


Note 1 




1 1 


1 







57. 


Bearer capability not authorized 


Note 3 




1 1 


1 


1 





58. 


Bearer capability not presently available 


Note 3 




1 1 


1 


1 1 




63. 


Service or option not available, 
unspecified 


" 




1 










65. 


Bearer service not implemented 
(continued) 


Notes 
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Table 10.5.123/3GPP TS 24.008 (concluded): Cause information element values 



Cause value 




Cause 


Cause 


Diag- 


Remarks 


Class 


Value 




num. 




nostic 




7 6 5 


4 3 2 


1 










1 


1 





68. 


ACM equal to or greater than AGMmax 






1 


1 


1 


69. 


Requested facility not implemented 


Note 1 




1 


1 1 





70. 


Only restricted digital information bearer 
capability is available 






1 


1 1 1 


1 


79. 


Service or option not implemented, 
unspecified 


- 




1 1 





1 


81. 


Invalid transaction identifier value 


- 




1 1 


1 1 


1 


87. 


User not member of GUG 


Notel 




1 1 


1 





88. 


Incompatible destination 


Incompatible parameter 
(Note 2) 


1 1 


1 1 


1 


91. 


Invalid transit network selection 


- 




1 1 


1 1 1 


1 


95. 


Semantically incorrect message 


- 




1 1 








96. 


Invalid mandatory information 


Information element 
identifier(s) 


1 1 





1 


97. 


IVIessage type non-existent or not 
implemented 


Message type 


1 1 


1 





98. 


IVIessage type not compatible with 
protocol state 


Message type 


1 1 


1 


1 


99. 


Information element non-existent or not 
implemented 


Information element 
identifier(s) (notes 6,7) 


1 1 


1 





100. 


Conditional IE error 


Information element 
identifier(s) (note 6) 


1 1 


1 


1 


101. 


Message not compatible with protocol 
state 


Message type 


1 1 


1 1 





102. 


Recovery on timer expiry 


Timer number (note 8) 


1 1 


1 1 1 


1 


111. 


Protocol error, unspecified 


- 




1 1 1 


1 1 1 


1 


127. 


Interworking, unspecified 


- 





All other values in the range to 3 1 shall be treated as cause 3 1 . 

All other values in the range 32 to 47 shall be treated as cause 47. 

All other values in the range 48 to 63 shall be treated as cause 63. 

All other values in the range 64 to 79 shall be treated as cause 79. 

All other values in the range 80 to 95 shall be treated as cause 95. 

All other values in the range 96 to 111 shall be treated as cause 111. 

All other values in the range 1 12 to 127 shall be treated as cause 127. 

NOTE 1 : Diagnostics for supplementary services are handled as follows: 

octet 5, bit 8: 

This is an extension bit as defined in the preliminary part of subclause 
protocol, this bit shall be set to 1 . If it is set to zero, the contents of the 

octet 5, bit 7-1: 

0000001 - Outgoing calls barred within CUG 

0000010 - No CUG selected 

000001 1 - Unknown CUG index 

0000100 - CUG index incompatible with requested basic service 

0000101 - CUG call failure, unspecified 
00001 10 - CLIR not subscribed 



10.5. In this version of this 
following octets shall be ignored. 



£75/ 



3GPP TS 24.008 version 1 0.10.0 Release 1 481 ETSI TS 1 24 008 VI 0.1 0.0 (201 3-04) 

0000111 -CCBS possible 

0001000 - CCBS not possible 

All other values shall be ignored. 

NOTE 2: The incompatible parameter is composed of the incompatible information element identifier. 

NOTE 3: The format of the diagnostic field for cause numbers 57, 58 and 65 is as shown in figure 10.5.88/3GPP 
TS 24.008 and tables 10.5.102/3GPP TS 24.008 to 10.5.115/3GPP TS 24.008. 

NOTE 4: The user supplied diagnostics field is encoded according to the user specification, subject to the 

maximum length of the cause information element. The coding of user supplied diagnostics should be 
made in such a way that it does not conflict with the coding described in note 9 below. 

NOTE 5: The new destination is formatted as the called party BCD number information element, including 
information element identifier. 

NOTE 6: Locking and non-locking shift procedures described in subclause 10.5.4.2 and clause 3 are applied. In 

principle, information element identifiers are ordered in the same order as the information elements in the 
received message. 

NOTE 7: When only the locking shift information element is included and no information element identifier 
follows, it means that the codeset in the locking shift itself is not implemented. 

NOTE 8: The timer number is coded in 1A5 characters, e.g., T308 is coded as "3" "0" "8". The following coding is 
used in each octet: 

bit 8: spare "0" 

bits 7-1: 1A5 character 

Octet 5 carries "3", octet 5a carries "0", etc. 

NOTE 9: The following coding is used for octet 5: 

bit 8 : 1 

bits 7-3: 00000 

bits 2-1: condition as follows: 

00 - unknown 

01 - permanent 
10 - transient 

10.5.4.11a CLIR suppression 

The CLIR suppression information element may be sent by the mobile station to the network in the SETUP message. 
The use is defined in 3GPP TS 24.081 [25]. 

The CLIR suppression information element is coded as shown in figure 10.5.96/3GPP TS 24.008. 

The CLIR suppression is a type 2 information element. 



CLIR suppression lEI ^ octet 1 



Figure 10.5.96/3GPP TS 24.008 CLIR suppression information element 
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10.5.4.11b CLIR invocation 

The CLIR invocation information element may be sent by the mobile station to the network in the SETUP message. The 
use is defined in 3GPP TS 24.081 [25]. 

The CLIR invocation information element is coded as shown in figure 10.5.97/3GPP TS 24.008. 

The CLIR invocation is a type 2 information element. 



CLIR invocation lEI 



octet 1 



Figure 10.5.97/3GPP TS 24.008 CLIR invocation information element 

10.5.4.12 Congestion level 

The purpose of the congestion level information element is to describe the congestion status of the call. 

The congestion level information element is coded as shown in figure 10.5.98/3GPP TS 24.008 and 
table 10.5.124/3GPP TS 24.008. 

The congestion level is a type 1 information element. 



8 



1 





Congestion level 
lEI 


Congestion level 



octet 1 

Figure 10.5.98/3GPP TS 24.008 Congestion level information element 
Table 1 0.5.1 24/3GPP TS 24.008: Congestion level information element 



Congestion level (octet 1 ) 

Bits 

4 3 2 1 

receiver ready 

1111 receiver not ready 

All other values are reserved. 



10.5.4.13 Connected number 

The purpose of the connected number information element is to identify the connected party of a call. 

The connected number information element is coded as shown in figure 10.5.99/3GPP TS 24.008. 

The connected number is a type 4 information element with a minimum length of 3 octets and a maximum length of 14 
octets. 
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8 


7 6 


5 


4 3 


2 1 


Connected number lEI 


Length of connected number contents 


0/1 
ext 


Type of number 


Number plan 
identification 


1 
ext 


Presentation 
indicator 



Spare 


Screening 
indicator 


Number digit 2 


Number digit 1 


Number digit 4 


Number digit 3 


note 2) 





octet 1 
octet 2 
octet 3 

note 1 ) 
octet 3a* 

note 1) 
octet 4* 

note 1) 
octet 5* 

note 1 1 



Figure 10.5.99/3GPP TS 24.008 

NOTE 1: The contents of octets 3,4,5, etc. ... are coded as shown in table 10.5.118/3GPP TS 24.008. The coding of 
octet 3a is defined in table 10.5.120/3GPP TS 24.008. 

NOTE 2: If the connected number contains an odd number of digits, bits 5 to 8 of the last octet shall be filled with 
the end mark coded as "1111". 

10.5.4.14 Connected subaddress 

The purpose of the connected subaddress information element is to identify a subaddress associated with the connected 
party of a call. 

The connected subaddress information element is coded as shown in figure 10.5.100/3GPP TS 24.008. 

The connected subaddress is a type 4 information element with a minimum length of 2 octets and a maximum length of 
23 octets. 



Connected subaddress I El 



Length of connected subaddress contents 



Type of 
subaddress 



odd/even 
indicator 








Spare 



Subaddress information 



octet 1 
octet 2 
octet 3* 

octet 4* 

etc. 



Figure 1 0.5.1 00/3GPP TS 24.008 

The coding for Type of subaddress, odd/even indicator, and subaddress information is in table 10.5.1 19/3GPP TS 
24.008. 

10.5.4.15 Facility 

The purpose of the facility information element is to transport supplementary service related information. Within the 
scope of 3GPP TS 24.008 the content of the Facility information field is an array of octets. The usage of this 
transportation mechanism is defined in 3GPP TS 24.080 [24]. 

The facility information element is coded as shown in figure 10.5.101/3GPP TS 24.008. 

The facility is a type 4 information element with a minimum length of 2 octets. No upper length limit is specified except 
for that given by the maximum number of octets in a L3 message (see 3GPP TS 44.006 [19]). 
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8 


7 6 5 4 3 2 


1 


1 Facility lEI 


Length of facility contents 


Facility information (see 3GPP TS 24.080 [24]) 



octet 1 
octet 2 
octet 3-?* 



Figure 10.5.101/3GPP TS 24.008 



1 0.5.4.1 6 High layer compatibility 

The purpose of the high layer compatibility information element is to provide a means which should be used by the 
remote user for compatibility checking. See annex B. 

The high layer compatibility information element is coded as shown in figure 10.5.102/3GPP TS 24.008 and 
table 10.5.125/3GPP TS 24.008. 

The high layer compatibility is a type 4 information element with a minimum length of 2 octets and a maximum length 
of 5 octets. 

NOTE: The high layer compatibility information element is transported transparently by a PLMN between a call 
originating entity (e.g. a calling user) and the addressed entity (e.g. a remote user or a high layer function 
network node addressed by the call originating entity). However, if explicitly requested by the user (at 
subscription time), a network which provides some capabilities to realize teleservices may interpret this 
information to provide a particular service. 



High layer compatibility lEI 


octet 1 




Length 


of high layer compatibility contents 




octet 2 


1 
ext 


coding 
standard 


interpretation 


presentat. 

method of 

protocol 

profile 


octet 3* 


0/1 
ext 


High layer characteristics identification 


octet 4* 


1 
ext 


Extended high layer characteristics 
identification 


octet 4a* 
(note) 



Figure 1 0.5.1 02/3GPP TS 24.008 High layer compatibility information element 

If the value part of the IE is empty, the IE indicates "not applicable". 

NOTE: Octet 4a may be present e.g. when octet 4 indicates Maintenance or Management, or audio visual. 

Table 1 0.5.1 25/3GPP TS 24.008: High layer compatibility information element 



Coding standard (octet 3) 

see ITU Recommendation Q.931. 

Interpretation (octet 3) 

see ITU Recommendation Q.931. 

Presentation method of protocol profile (octet 3) 
see ITU Recommendation Q.931. 

High layer characteristics identification (octet 4) 

see ITU Recommendation Q.931. 

Extended high layer characteristics identification (octet 4a) 

see ITU Recommendation Q.931. 
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10.5.4.16.1 Static conditions for the high layer compatibility IE contents 

Either the value part of the IE is empty, or it contains at least octet 3 and 4. 

10.5.4.17 Keypad facility 

The purpose of the keypad facility information element is to convey IA5 characters, e.g. entered by means of a terminal 
keypad (see note). 

The keypad facility information element is coded as shown in figure 10.5.103/3GPP TS 24.008. 

The keypad facility is a type 3 information element with 2 octets length. 



8 


7 6 5 4 3 2 


1 




Keypad facility lEl 


Spare 



Keypad information (IA5 character) 



octet 1 
octet 2 
Figure 1 0.5.1 03/3GPP TS 24.008 Keypad facility information element 

NOTE: In the 3GPP system this information element is only used to transfer one DTMF digit (0, 1, ... , 9, A, B, 
C, D, *, #) as one IA5 character. 



1 0.5.4.1 8 Low layer compatibility 

The purpose of the low layer compatibility information element is to provide a means which should be used for 
compatibility checking by an addressed entity (e.g., a remote user or an interworking unit or a high layer function 
network node addressed by the calling user). The low layer compatibility information element is transferred 
transparently by a PLMN between the call originating entity (e.g. the calling user) and the addressed entity. 

Except for the information element identifier, the low layer compatibility information element is coded as in ITU 
recommendation Q.93 1 . 

For backward compatibility reasons coding of the modem type field according to ETS 300 102-1 (12-90) shall also be 
supported. 

The low layer compatibility is a type 4 information element with a minimum length of 2 octets and a maximum length 
of 18 octets. 



Low layer compatibility I El 



Length of the low layer compatibility contents 



The following octets are coded 

as described in 

ITU Recommendation Q.931 

(Coding of the modem type according to both Q.931 and 

ETS 300 102-1 (12-90) shall be accepted) 



octet 1 
octet 2 
octet 3* 



Figure 1 0.5.1 04/3GPP TS 24.008 Low layer compatibility information element 

If the value part of the IE is empty, the IE indicates "not applicable". 

10.5.4.19 More data 

The more data information element is sent by the mobile station to the network or to the network to the mobile station 
in a USER INFORMATION message. The presence of the more data information element indicates to the destination 
remote user/mobile station that another USER INFORMATION message will follow containing information belonging 
to the same block. 
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The use of the more data information element is not supervised by the network. 

The more data information element is coded as shown in figure 10.5.105/3GPP TS 24.008. 

The more data is a type 2 information element. 



More data I El 



octet 1 



Figure 1 0.5.1 05/3GPP TS 24.008 More data information element 

10.5.4.20 Notification indicator 

The purpose of the notification indicator information element is to indicate information pertaining to a call. 

The notification indicator element is coded as shown in figure 10.5.106/3GPP TS 24.008 and table 10.5.126/ 3GPP TS 
24.008. 

The notification indicator is a type 3 information element with 2 octets length. 



octet 1 
octet 2 



Figure 1 0.5.1 06/3GPP TS 24.008 Notification indicator information element 
Table 1 0.5.1 26/3GPP TS 24.008: Notification indicator information element 



8 


7 


6 


5 4 3 


2 


1 




Notification indicator lEI 


1 
ext 


Notification description 



Notification description (octet 2) 




Bits 




7 6 5 4 3 2 1 







User suspended 


1 


User resumed 


10 


Bearer change 


All other values are reserved. 





10.5.4.21 Progress indicator 

The purpose of the progress indicator information element is to describe an event which has occurred during the life of 
a call. 

The progress indicator information element is coded as shown in figure 10.5.107/3GPP TS 24.008 and 
table 10.5.127/3GPP TS 24.008. 

The progress indicator is a type 4 information element with a length of 4 octets. 



octet 1 

octet 2 

octet 3 
octet 4 



Figure 10.5.107/3GPP TS 24.008 Progress indicator information element 



8 


7 6 


5 


4 3 2 


1 


Progress indicator lEI 


Length of progress indicator contents 


1 
ext 


coding 
standard 



spare 


location 


1 
ext 


progress description 
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Table 1 0.5.1 27/3GPP TS 24.008: Progress indicator information element 



Coding standard (octet 3) 

Bits 

7 6 

Standardized coding, as described in ITU-T Rec. Q.931 

1 Reserved for other international standards 

1 National standard 

1 1 Standard defined for the GSMBPLMNS as described below 

Coding standards other than "1 1 - Standard defined for the GSM PLIVINS" shall not be 
used if the progress description can be represented with the GSIVIRstandardized 
coding. 

The mobile station or network need not support any other coding standard than "1 1 - 
Standard defined for the GSM PLMNS". 

If a progress indicator IE indicating a coding standard not supported by the receiver is 
received, progress description "Unspecific" shall be assumed. 

Location (octet 3) 



Bits 
4 3 



User 

Private network serving the local user 
Public network serving the local user 
Public network serving the remote user 
Private network serving the remote user 
Network beyond interworking point 



All other values are reserved. 

Note: Depending on the location of the users, the local public network and remote 
public network may be the same network. 

Progress description (octet 4) 

Bits 

7 6 5 4 3 2 1 No. 

1 1. Callis not end-to-end PLMN/ISDN, further call 

progress information may be available in-band 
Destination address in non-PLMN/ISDN 
Origination address in non-PLMN/ISDN 
Call has returned to the PLMN/ISDN 
In-band information or appropriate pattern now 
available 

In-band multimedia CAT available 
Call is end-to-end PLMN/ISDN 
Queueing 
Unspecific 












1 


1 


3. 








1 








4. 





1 











8. 





1 








1 


9. 


1 














32 


1 














64 


All other values 









1 0.5.4.21 a Recall type $(CCBS)$ 

The purpose of the recall type information element is to describe the reason for the recall. 

The recall type information element is coded as shown in Figure 10.5.108/3GPP TS 24.008 and Table 10.5.128/3GPP 
TS 24.008. 

The recall type is a type 3 information element with 2 octets length. 



octet 1 
octet 2 
Figure 1 0.5.1 08/3GPP TS 24.008 Recall type information element 



8 


7 


6 


5 4 


3 


2 1 


recall type lEI 








spare 






recall type 
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Table 1 0.5.1 28/3GPP TS 24.008: Recall type information element 



recall type (octet 2, bits 1 to 4) 


Bits 




3 2 1 







-CCBS 


1 


} 


to 


} - shall be treated as CCBS (intended for other similar types of Recall) 


1 1 


} 


1 1 1 


- reserved 



1 0.5.4.21 b Redirecting party BCD number 

The purpose of the redirecting party BCD number information element is to identify the redirecting party. 

The redirecting party BCD number information element is coded as shown in figure 10.5.108a/3GPP TS 24.008. 

The redirecting party BCD number is a type 4 information element. In the network to mobile station direction it has a 
minimum length of 3 octets and a maximum length of 19 octets. 



octet 1 

octet 2 
octet 3 
(note 1) 
octet 3a* 
(note 1) 
octet 4* 
(note 1) 
octet 5* 
(note 1) 



Figure 1 0.5.1 08a/3GPP TS 24.008 
Redirecting party BCD number information element 

NOTE 1: The contents of octets 3, 4, etc. are coded as shown in table 10.5.118/3GPP TS 24.008. The coding of 
octet 3a is defined in table 10.5.120/3GPP TS 24.008. 

NOTE 2: If the redirecting party BCD number contains an odd number of digits, bits 5 to 8 of the last octet shall be 
filled with an end mark coded as "1111". 



8 


7 6 


5 


4 3 


2 1 


Redirecting party BCD number lEI 


Length of redirecting party BCD number contents 


0/1 
ext 


type of 
number 


Numbering plan 
identification 


1 
ext 


presentat. 
indicator 



spare 


Screening 
indicator 


Number digit 2 


Number digit 1 


Number digit 4 


Number digit 3 










Note 2) 





10.5.4.21c 



Redirecting party subaddress 



The purpose of the Redirecting party subaddress is to identify a subaddress associated with the redirecting party. For the 
definition of a subaddress see Rec. ITU-T 1.330. 

The Redirecting party subaddress information element is coded as shown in figure 10.5.108b/3GPP TS 24.008 and 
table 10.5.121/3GPP TS 24.008. 

The Redirecting party subaddress is a type 4 information element with a minimum length of 2 octets and a maximum 
length of 23 octets. 
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Redirecting party Subaddress lEI 



1 
ext 



Length of redirecting party subaddress contents 



type of 
subaddress 



odd/ev 
Indica 











Subaddress information 



octet 1 
octet 2 
octet 3* 
octet 4* 

etc. 



Figure 1 0.5.1 08b/3GPP TS 24.008 
Redirecting party subaddress information element 

10.5.4.22 Repeat indicator 

The purpose of the repeat indicator information element is to indicate how the associated repeated information elements 
shall be interpreted, when included in a message. The repeat indicator information element is included immediately 
before the first occurrence of the associated information element which will be repeated in a message. "Mode 1" refers 
to the first occurrence of that information element, "mode 2" refers to the second occurrence of that information element 
in the same message. 

The repeat indicator information element is coded as shown in figure 10.5.109/3GPP TS 24.008 and 
table 10.5.129/3GPP TS 24.008. 

The repeat indicator is a type 1 information element. 



1 

octet 1 

Figure 1 0.5.1 09/3GPP TS 24.008 Repeat indicator information element 
Table 1 0.5.1 29/3GPP TS 24.008: Repeat indicator information element 





repeat indicator 
lEI 


repeat indication 



Repeat indication (octet 1) 




Bits 










4 3 


2 


1 












1 


Circular for successive selection 
"mode 1 alternate mode 2" 







1 





Support of fallback - mode 1 preferred, mode 2 selected if setup of 








mode 1 fails 







1 


1 


reserved: was allocated in earlier phases of the protocol 




1 








Service change and fallbacl< - mode 1 alternate mode 2, 
preferred 


mode 1 


All other values are reserved. 





1 0.5.4.22a Reverse call setup direction 

This information element may be included in a MODIFY and MODIFY COMPLETE message to indicate that the 
direction of the data call to which the MODIFY message relates is opposite to the call setup direction. 

The reverse call setup direction information element is coded as shown in figure 10.5.1 10/3GPP TS 24.008. 

The reverse call setup direction is a type 2 information element 
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reverse call setup direction lEI 



octet 1 



Figure 1 0.5.11 0/3GPP TS 24.008 Reverse call setup direction information element 

1 0.5.4.22b SETUP Container $(CCBS)$ 

This information element contains the contents of a SETUP message (Mobile Station to Network). This means that the 
Call Control protocol discriminator IE, the Transaction Identifier IE and the Setup message type IE are not included. 

The SETUP Container information element is coded as shown in figure 10.5.111/3GPP TS 24.008. 

The SETUP Container is a type 4 information. No upper length limit is specified except for that given by the maximum 
number of octets in a L3 message (see 3GPP TS 44.006 [19]). 



8 


7 


6 5 4 3 


2 


1 


1 SETUP Container lEI 


Length of SETUP container contents 


SETUP message 



octet 1 
octet 2 

octet 3-n 



Figure 1 0.5.1 11/3GPP TS 24.008 Octet j (j = 3, 4 ... n) is the unchanged octet j of the SETUP message. 

10.5.4.23 Signal 

The purpose of the signal information element is to allow the network to convey information to a user regarding tones 
and alerting signals (see subclauses 5.2.2.3.2 and 7.3.3.). 

The signal information element is coded as shown in figure 10.5.1 12/3GPP TS 24.008 and 
table 10.5.130/3GPP TS 24.008. 

The signal is a type 3 information element with 2 octets length. 



8 


7 


6 


5 4 3 


2 


1 


1 Signal lEI 


Signal value 



octet 1 



octet 2 



Figure 10.5.112/3GPP TS 24.008 Signal information element 
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Table 1 0.5.1 30/3GPP TS 24.008: Signal information element 



Signal val 


ue 


(octet 2) 






Bits 
















8 7 


6 


5 


4 


3 


2 



























dial tone on 






















ring back tone on 

















1 





Intercept tone on 

















1 




network congestion tone on 














1 








busy tone on 














1 







confirm tone on 














1 


1 





answer tone on 














1 


1 




call waiting tone on 











1 











off-hook warning tone on 





1 


1 


1 


1 


1 




tones off 


1 








1 


1 


1 




alerting off 


All other values are 


eserved. 





10.5.4.24 SS Version Indicator 

The purpose of the SS version indicator information element is to aid the decoding of the Facility information element 
as described in 3GPP TS 24.010 [21]. Within the scope of 3GPP TS 24.008 the contents of the SS Version information 
field is an array of one or more octets. The usage of the SS version information field is defined in 3GPP TS 24.080 [24]. 

The SS version indicator information element is coded as shown in figure 10.5.113/3GPP TS 24.008. 

The SS version indicator is a type 4 information element with a minimum length of 2 octets. No upper length limit is 
specified except for that given by the maximum number of octets in a L3 message (see 3GPP TS 44.006 [19]). 



octet 1 
octet 2 
octet 3* 



8 


7 6 5 4 3 2 


1 


SS version indicator IE! 


Length of SS version indicator contents 


SS version information (see 3GPP TS 24.080 [24]) 



Figure 10.5.1 13/3GPP TS 24.008 

NOTE: Usually, this information element has only one octet of content. 

10.5.4.25 User-user 

The purpose of the user-user information element is to convey information between the mobile station and the remote 
ISDN user. 

The user-user information element is coded as shown in figure 10.5.114/3GPP TS 24.008 and table 10.5.131/ 
3GPP TS 24.008. There are no restrictions on the content of the user-user information field. 

The user-user is a type 4 information element with a minimum length of 3 octets and a maximum length of either 35 or 

131 octets. In the SETUP message the user-user information element has a maximum size of 35 octets in a 

GSM PLMN. In the USER INFORMATION, ALERTING, CONNECT, DISCONNECT, PROGRESS, RELEASE and 

RELEASE COMPLETE messages the user-user information element has a maximum size of 131 octets in a 

GSM PLMN. 

In other networks than GSM PLMNs the maximum size of the user-user information element is 35 or 131 octets in the 
messages mentioned above. The evolution to a single maximum value is the long term objective; the exact maximum 
value is the subject of further study. 

NOTE: The user-user information element is transported transparently through a GSM PLMN. 
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User-user lEI 



Length of user-user contents 



User-user protocol discriminator 



User-user information 



octet 1 

octet 2 
octet 3 

octet 4* 



octet N* 



Figure 1 0.5.11 4/3GPP TS 24.008 User-user information element 



Table 10.5.131/3GPP TS 24.008: User-user information element 



User-use 


protocol discriminator (octet 3) 


Bits 














8 7 6 


5 


4 


3 


2 


1 






















User specific protocol (Note 1) 

















1 


OSI high layer protocols 














1 





X.244 (Note 2) 














1 


1 


Reserved for system management convergence 
function 











1 








IA5 characters (Note 3) 











1 


1 


1 


Rec.V.120 rate adaption 








1 











0.931 (1.451) user-network call control messages 





1 














Reserved for other network layer or 


through 












layer 3 protocols 


1 


1 


1 


1 


1 


1 




1 



















through 












National use 


1 





1 


1 


1 







1 





1 


1 


1 


1 


3GPP capability exchange protocol (NOTE 4) 


1 


1 














Reserved for other network 


through 












layer or layer 3 protocols 


1 1 1 


1 


1 


1 


1 







All other values are 


reserved. 




NOTE 1 : 


The user 


information is 


structured according to user needs. 


NOTE 2: 


The user 


information is 


structured according to Rec.X.244 which specifies 




the structure 


of X.25 call user data. 


NOTE 3: 


The user 


information consists of IA5 characters. 


NOTE 4: 


When the i 


jser 


-user protocol discriminator is set to "3GPP capability 




exchange protocol", the 


user-user information is coded according to 




3GPPTS24.279[116]. 





10.5.4.26 Alerting Pattern $(NIA)$ 

The purpose of the Alerting Pattern information element is to allow the network to convey information related to the 
alert to be used by the MS (see 3GPP TS 22.101 [8]). 

The Alerting Pattern information element is coded as shown in figure 10.5.1 15/3GPP TS 24.008 and 
table 10.5.132/3GPP TS 24.008. 

The Alerting Pattern IE is a type 4 information element with 3 octet length. 
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8 


7 6 5 


4 3 2 


1 


Alerting Pattern lEI 


length of alerting pattern content 






spare 


Alerting Pattern 
value 



octet 1 
octet 2 

octet 3 



Figure 1 0.5.11 5/3GPP TS 24.008 Alerting Pattern information element 
Table 1 0.5.1 32/3GPP TS 24.008: Alerting Pattern information element 



Alerting Pattern value (octet 3) 

Bits 

4 3 2 1 

alerting pattern 1 
1 alerting pattern 2 
10 alerting pattern 3 

10 alerting pattern 5 

10 1 alerting pattern 6 

110 alerting pattern 7 

111 alerting pattern 8 

10 alerting pattern 9 

all other values are reserved 



Alerting pattern 1, 2 and 3 indicate alerting levels 0, 1 and 2. 
Alerting pattern 5 to 9 indicate alerting categories 1 to 5 

1 0.5.4.27 Allowed actions $(CCBS)$ 

The purpose of the Allowed actions information element is to provide the mobile station with information about further 
allowed procedures. 

The Allowed actions information element is coded as shown in figure 10.5. 1 16/3GPP TS 24.008 and 
table 10.5.133/3GPP TS 24.008. 

The Allowed actions is a type 4 information element with 3 octets length. 



8 


7 


6 5 4 3 


2 


1 


Allowed Actions IE! 


Length of allowed actions contents 


CCBS 
act. 






spare 









octet 1 
octet 2 
octet 3 
Figure 1 0.5.1 16/3GPP TS 24.008 Allowed actions information element 

Table 1 0.5.1 33/3GPP TS 24.008: Allowed actions information element 



CCBS activation (octet 3) 



Bits 
8 

1 



Activation of CCBS not possible 
Activation of CCBS possible 
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10.5.4.28 stream Identifier 

The purpose of the stream identifier (SI) information element is to associate a particular call with a Radio Access Bearer 
(RAB), and to identify whether a new traffic channel shall be assigned within the interface controlled by these 
signalling procedures. The SI value indicated in the CC protocol shall be sent in the RAB setup message. And mobile 
station is informed the relationship between the call and the RAB. 

The Stream identifier information element is coded as shown in figure 10.5.1 17/3GPP TS 24.008 and 
table 10.5.134/3GPP TS 24.008. 

The Stream Identifier is a type 4 information element with 3 octets length. 



Stream Identifier lEI 



Lengtii of Stream Identifier contents 



Stream Identifier Value 



octet 1 
octet 2 
octet 3 



Figure 1 0.5.11 7/3GPP TS 24.008: Stream Identifier information element 
Table 1 0.5.1 34/3GPP TS 24.008: Stream Identifier information element 



Stream Identifier value(octet 3) 

Bit 

8 7 6 5 4 3 2 1 

00000000 No bearer 

1 1 



11111111 255 



1 0.5.4.29 Network Call Control Capabilities 

The purpose of the Network Call Control Capabilities information element is to identify the call control capabilities of 
the network. The contents might affect the manner in which the mobile station handles the call. 

The Network Call Control Capabilities information element is coded as shown in figure 10.5.118/3GPP TS 24.008 and 
table 10.5.135/3GPP TS 24.008. 

The Network Call Control Capabilities is a type 4 information element with a length of 3 octets. 



8 


7 6 5 4 3 2 


1 


Networl< Call Control Capabilities lEI 


Length of NW Call Control Cap. contents 






spare 


IVICS 



octet 1 
octet 2 
octet 3 
Figure 1 0.5.1 18/3GPP TS 24.008 Network Call Control Capabilities information element 

Table 1 0.5.1 35/3GPP TS 24.008: Network Call Control Capabilities 



IVICS (octet 3, bill) 

This value indicates that the network does not support the multicall. 

J This value indicates that the network supports the multicall. 
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10.5.4.30 Cause of No CLI 

Cause of No CLI information element provides the mobile station the detailed reason why Calling party BCD number is 
not notified (see 3GPP TS 24.081 [25]). 

The Cause of No CL/ information element is coded as shown in figure 10.5.118a/3GPP TS 24.008 and 
table 10.5.135a/3GPPTS 24.008. 

The Cause of No CLI is a type 4 information element with the length of 3 octets. 



8 


7 


6 5 4 3 


2 


1 


Cause of No CLI lEI 


Length of Cause of No CLI contents 


Cause of No CLI 



octet 1 
octet 2 
octet 3 



Figure 1 0.5.11 8a/3GPP TS 24.008 Cause of No CLI information element 
Table 1 0.5.1 35a/3GPP TS 24.008: Cause of No CLI information element 



Cause of No CLI (octet 3) 




Bits 




8 7 6 5 4 3 2 1 




00000000 


Unavailable 


1 


Reject by user 


10 


Interaction with other service 


1 1 


Coin line/payphone 


Other values shall be interpreted as "Unavailable". 



10.5.4.31 Void 

10.5.4.32 Supported codec list 

The purpose of the Supported Codec List information element is to provide the network with information about the 
speech codecs supported by the mobile. 

The Supported Codec List information element is coded as shown in figure 10.5.118c/3GPP TS 24.008. 

The Supported Codec List information element is a type 4 information element with a minimum length of 5 octets and a 
maximum length of m+3 octets. 

Speech codec information belonging to GERAN and UTRAN shall be conveyed by this information element. 
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8 


7 6 5 4 3 2 


1 


Supported Codec List lEI 


Length Of Supported Codec list 


System Identification 1 (SysID 1) 


Length Of Bitmap for SysID 1 


Codec Bitmap for SysID 1 , bits 1 to 8 


Codec Bitmap for SysID 1 , bits 9 to 16 


System Identification 2 (SysID 2) 


Length Of Bitmap for (SysID 2) 


Codec Bitmap for (SysID 2), bits 1 to 8 


Codec Bitmap for (SysID 2), bits 9 to 16 


System Identification x (SysID x) 


Length Of Bitmap for (SysID x) 


Codec Bitmap for (SysID x), bits 1 to 8 


Codec Bitmap for (SysID x), bits 9 to 16 



octet 1 
octet 2 

octet 3 

octet 4 

octet 5 
octet 6 
octet j 

octet j+1 

octet j+2 
octet j+3 
octet m 

octet m+1 

octet m+2 
octet m+3 



Figure 10.5.118c/3GPP TS 24.008 Supported codec list information element 
Table 1 0.5.4.1 35c/3GPP TS 24.008: Supported Codec List information element 



Octets, (j), mete 

SysID indicates the radio access technology for which the subsequent Codec 

Bitmap indicates the supported codec types. 

Coding of this Octet is defined in 3GPP TS 26.1 03 [83]. 

Octet 4, (j+1), m+1 etc 

Length Of Codec Bitmap for SysID indicates the number of octets included in the 

list for the given SysID. 

Octets (5 & 6), (j+2 & j+3), (m+2 & m+3) etc 

The coding of the Codec Bitmap is defined in 3GPP TS 26.103 [83]. 

NOTE: If the Codec Bitmap for a SysID is 1 octet, it is an indication that all codecs 
of the 2"'^ octet are not supported. If the Codec Bitmap for a SysID is more than 2 
octets, the network shall ignore the additional octet(s) of the bitmap and process 
the rest of the information element. 



10.5.4.33 Service category 

The purpose of the Service category information element is to provide the network with information about services 
invoked by the user equipment. 

The Service category information element is coded as shown in figure 10.5.118d/3GPP TS 24.008 and 
table 10.5.135d/3GPP TS 24.008 

The Service category is a type 4 information element with a minimum length of 3 octets. 
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8 


7 6 5 4 3 2 


1 


Service Category lEI 


Length of Service Category 



spare 


Emergency Service Category Value 



octet 1 
octet 2 
octet 3 



Figure 1 0.5.11 8d/3GPP TS 24.008 Service Category information element 

Table 1 0.5.1 35d/3GPP TS 24.008: Service Category information element 

Emergency Service Category Value (octet 3) 

The meaning of the Emergency Category Value is derived from the following settings (see 3GPP TS 22.101 [8] clause 

10): 

Bit 1 Police 

Bit 2 Ambulance 

Bit 3 Fire Brigade 

Bit 4 Marine Guard 

Bit 5 IVIountain Rescue 

Bit 6 manually initiated eCall 

Bit 7 automatically initiated eCall 

Bit 8 is spare and set to "0" 

Mobile station may set one or more bits to "1 " 

If more than one bit is set to "1", routing to a combined Emergency centre (e.g. ambulance and fire brigade in Japan) is 
required. If the MSC can not match the received service category to any of the emergency centres, it shall route the call 
to an operator defined default emergency centre. 

If no bit is set to "1 ", the MSC shall route the Emergency call to an operator defined default emergency centre. 

A mobile station initiating an eCall shall set either bit 6 or bit 7 to "1". The networl< may use the information indicated in bit 

6 and bit 7 to route the manually or automatically initiated eCall to an operator defined emergency call centre. 



10.5.4.34 Redial 

The purpose of the Redial information element is to indicate to the network that a call is the result of a redial attempt to 
switch from speech to multimedia or vice-versa. 

The Redial information element is coded as shown in figure 10.5.1 18e/3GPP TS 24.008 

The Redial is a type 2 information element with a length of 1 octet. 



1 



Redial lEI octet 1 



Figure 10.5.1 18e/3GPP TS 24.008 Redial information element 



10.5.4.35 Network-initiated Service Upgrade indicator 

The purpose of the Network-initiated Service Upgrade indicator information element is to indicate to the mobile station 
that the in-call modification procedure is due to a network-initiated upgrade from speech to UDI/RDI multimedia (see 
3GPPTS 23.172 [97]). 

The Network- initiated Service Upgrade indicator information element is coded as shown in figure 10.5.118f/3GPP TS 
24.008. 
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The Network-initiated Service Upgrade indicator is a type 2 information element with a length of 1 octet. 



Network-initiated Service Upgrade indicator I El 



octet 1 



Figure 10.5.118f/3GPP TS 24.008 Network-initiated Service Upgrade indicator information element 



10.5.5 GPRS mobility management information elements 
10.5.5.1 Attach result 

The purpose of the attach result information element is to specify the result of a GPRS attach procedure. 

The attach result is a type 1 information element. 

The attach result information element is coded as shown in figure 10.5.1 17a/3GPP TS 24.008 and 
table 10.5.134a/3GPPTS 24.008. 



Attach result 
lEI 


FOP 


Result of 
attach 



octet 1 

Figure 10.5.117a/3GPP TS 24.008: Attach result information element 
Table 1 0.5.1 34a/3GPP TS 24.008: Attach result information element 



Result of attach (octet 1 ) 

Bits 

3 2 1 

1 GPRS only attached 

1 1 Combined GPRS/IMSI attached 

All other values are reserved. 

Follow-on proceed (octet 1 ) 

Bit 

4 

Follow-on proceed 

1 No follow-on proceed 

Follow-on proceed is applicable only in lu mode. This indication shall be ignored if 
received in A/Gb mode. 



10.5.5.2 Attach type 

The purpose of the attach type information element is to indicate the type of the requested attach, i.e. whether the MS 
wants to perform a GPRS or combined GPRS attach. 

The attach type is a type 1 information element. 

The attach type information element is coded as shown in figure 10.5.117b/3GPP TS 24.008 and table 10.5.135b/3GPP 
TS 24.008. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



499 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



1 



Attach type 
lEI 


FOR 


Type of attach 



octet 1 



Figure 1 0.5.11 7b/3GPP TS 24.008: Attach type information element 
Table 1 0.5.1 35b/3GPP TS 24.008: Attach type information element 



Type of attach (octet 1 , bit 1 to 3) 
Bits 

3 2 1 

1 GPRS attach 

1 Not used. This value was allocated in earlier versions of the protocol 
(Note1) 

1 1 Combined GPRS/II\/ISI attach 

1 Emergency attach 

All other values are interpreted as GPRS attach in this version of the protocol. 

Follow-on request (octet 1 , bit 4) 

Bits 

4 

No follow-on request pending 

1 Follow-on request pending 

Follow-on request pending is applicable only in lu mode. 



NOTE 1 : The code point "01 0" if received by the networl<, it shall be interpreted as 
"Combined GPRS/II\/ISI attach". 



10.5.5.3 Ciphering algorithm 

The purpose of the ciphering algorithm information element is to specify which ciphering algorithm shall be used. 

The ciphering algorithm is a type 1 information element. 

The ciphering algorithm information element is coded as shown in figure 10.5. 1 19/3GPP TS 24.008 and 
table 10.5.136/3GPP TS 24.008. 



octet 1 



Ciphering algorithm 
lEI 



spare 


Type of 
algorithm 



Figure 10.5.119/3GPP TS 24.008: Ciphering aigorithm information element 
Table 1 0.5.1 36/3GPP TS 24.008: Ciphering algorithm information element 



Type of ciph 


ering algorithm (octet 1) 


Bits 




3 2 1 







ciphering not used 


1 


GPRS Encryption Algorithm GEA/1 


1 


GPRS Encryption Algorithm GEA/2 


1 1 


GPRS Encryption Algorithm GEA/3 


1 


GPRS Encryption Algorithm GEA/4 


1 1 


GPRS Encryption Algorithm GEA/5 


1 1 


GPRS Encryption Algorithm GEA/6 


1 1 1 


GPRS Encryption Algorithm GEA/7 
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10.5.5.4 TMSI status 

The purpose of the TMSI status information element is to indicate whether a valid TMSI is available in the MS or not. 

The TMSI status is a type 1 information element. 

The TMSI status information element is coded as shown in figure 10.5.120/3GPP TS 24.008 and 
table 10.5.137/3GPP TS 24.008. 



8 


7 6 


5 


4 


3 


2 


1 


TMSI status 
lEI 






spare 





TMSI 
flag 



octet 1 

Figure 10.5.120/3GPP TS 24.008: TMSI status information element 
Table 10.5.137/3GPP TS 24.008: TMSI status information element 



TMSI flag (octet 1 ) 

Bit 

1 

no valid TMSI available 

1 valid TMSI available 



10.5.5.5 Detach type 

The purpose of the detach type information element is to indicate which type of detach is requested by the MS. In the 
network to MS direction the detach type information element is used to indicate the reason why a detach request is sent. 

The detach type is a type 1 information element. 

The detach type information element is coded as shown in figure 10.5.121/3GPP TS 24.008 and 
table 10.5.138/3GPP TS 24.008. 



octet 1 



Detach type 
lEI 


Power 
off 


Type of detach 



Figure 10.5.121/3GPP TS 24.008: Detach type information element 
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Table 1 0.5.1 38/3GPP TS 24.008: Detach type information element 



Type of detach (octet 1 ) 

In the MS to network direction: 

Bits 

3 2 1 

1 GPRS detach 

1 IMSI detach 

1 1 Combined GPRS/IMSI detach 

All other values are interpreted as Combined GPRS/IMSI detach by this version of the 
protocol. 

In the network to MS direction: 

Bits 

3 2 1 

1 re-attach required 

1 re-attach not required 

1 1 IMSI detach (after VLB failure) 

All other values are interpreted as re-attach not required by this version of the protocol. 

Power off (octet 1 ) 

In the MS to network direction: 

Bit 

4 

normal detach 

1 power switched off 

In the network to MS direction the Power off b\\. shall be spare and set to zero. 



10.5.5.6 DRX parameter 

The purpose of the DRX parameter information element is to indicate whether the MS uses DRX mode or not. 

The DRX parameter is a type 3 information element with a length of 3 octets. 

The value part of a DRX parameter information element is coded as shown in table 10.5.139/3GPP TS 24.008. 



octet 1 
octet 2 



8 7 6 5 


4 


3 


2 1 


DRX parameter lEI 


SPLIT PG CYCLE CODE 


CN Specific DRX cycle length 

coefficient 

and 

DRX value for SI mode 


SPLIT 

on 
CCCH 


non-DRX 
timer 



octet 3 



Figure 1 0.5.1 22/3GPP TS 24.008: DRX parameter information element 
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Table 1 0.5.1 39/3GPP TS 24.008: DRX parameter information element 



SPLIT PG CYCLE CODE, octet 2 


The octet contains the binary coded value of the SPLIT PG CYCLE CODE. The SPLIT 


PG CYCLE value is 


5 derived from the SPLIT PG CYCLE CODE as follows: 











704 (equivalent to no DRX) 


1 to 64 


[ 






1 to 64, respectively 


65 








71 


66 








72 


67 








74 


68 








75 


69 








77 


70 








79 


71 








80 


72 








83 


73 








86 


74 








88 


75 








90 


76 








92 


77 








96 


78 








101 


79 








103 


80 








107 


81 








112 


82 








116 


83 








118 


84 








128 


85 








141 


86 








144 


87 








150 


88 








160 


89 








171 


90 








176 


91 








192 


92 








214 


93 








224 


94 








235 


95 








256 


96 








288 


97 








320 


98 








352 


All other values are 


reserved and shall be interpreted as 1 by this version of the 


protocol. 








SPLIT 


on 


CCCH, octet3(bit4) 









Split pg cycle on 


CCCH is not supported by the mobile station 


1 




Split pg cycle on 


CCCH is supported by the mobile station 


non-DRX timer, octet 3 




bit 










3 2 
















no non-DRX mode after transfer state 







max. 


1 sec non- 


DRX mode after transfer state 


1 





max. 


2 sec non- 


DRX mode after transfer state 


1 




max. 


4 sec non- 


DRX mode after transfer state 


1 





max. 


8 sec non- 


DRX mode after transfer state 


1 




max. 


1 6 sec non 


-DRX mode after transfer state 


1 1 





max. 


32 sec non 


-DRX mode after transfer state 


1 1 




max. 


64 sec non 


-DRX mode after transfer state 
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CN Specific DRX cycle length coefficient and DRX value for S1 mode, octet 3 

This field represents two separate values. For lu mode, it represents the 'CN domain 
specific DRX cycle length' as defined in 3GPP TS 25.331 [23c]. For S1 mode, it 
represents the DRX cycle parameter 'T' as defined in 3GPP TS 36.304 [121]. 

bit 

8 7 6 5 lu and SI mode specific 

For lu mode, CN Specific DRX cycle length coefficient not specified by 
the MS, ie. the system information value 'CN domain specific DRX cycle 
length' is used . For SI mode, DRX value not specified by the MS. 

1 1 CN Specific DRX cycle length coefficient 6 and T = 32 

1 1 1 CN Specific DRX cycle length coefficient 7 and T = 64 
10 CN Specific DRX cycle length coefficient Sand T= 128 

1 1 CN Specific DRX cycle length coefficient 9 and T = 256 

All other values shall be interpreted as "CN Specific DRX cycle length coefficient not 
specified by the MS " and "DRX value not specified by the MS" by this version of the 
protocol. 

NOTE: For lu mode and SI mode, this field (octet 3 bits 8 to 5) is used, but was 
spare in earlier versions of this protocol. 



10.5.5.7 Force to standby 

The purpose of the force to standby information element is to force the MS to stop the READY timer in order to prevent 
the MS to perform cell updates. 

In lu mode, the network shall always indicate /orce to standby not indicated in the force to standby information 
element. 

The /orce to standby is a type 1 information element. 

The force to standby information element is coded as shown in figure 10.5.123/3GPP TS 24.008 and 
table 10.5.140/3GPP TS 24.008. 



8 



1 



Force to standby 
lEI 



spare 


Force to 
standby value 



octet 1 

Figure 10.5.123/3GPP TS 24.008: Force to sfandby information element 
Table 10.5.140/3GPP TS 24.008: Force to sfanc/by information element 



Force to standby value (octet 1 ) 

Bits 

3 2 1 

Force to standby not indicated 

1 Force to standby indicated 

All other values are interpreted as 

force to standby not indicated by this version of the protocol. 



10.5.5.8 P-TMSI signature 

The purpose of the P-TMSI signature information element is to identify a GMM context of an MS. 
The P-TMSI signature is a type 3 information element with 4 octets length. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



504 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



The P-TMSI signature information element is coded as shown in figure 10.5.124/3GPP TS 24.008 and 
table 10.5.141/3GPP TS 24.008. 



P-TMSI signature lEI 



P-TMSI signature value 



octet 1 
octet 2 

octet 4 



Figure 10.5.124/3GPP TS 24.008: P-TMSI signature information element 
Table 10.5.141/3GPP TS 24.008: P-TMSI signature information element 



P-TMSI signature value 

Octets 2, 3 and 4 contain the binary representation of the P-TMSI signature. 

Bit 1 of octet 4 is the least significant bit and bit 8 of octet 2 is the most significant bit. 



1 0.5.5.8a P-TMSI signature 2 

The purpose of the P-TMSI signature 2 information element is to identify a GMM context of an MS. 

The P-TMSI signature 2 is a type 4 information element with 5 octets length. 

The P-TMSI signature 2 information element is coded as shown in figure 10.5.124a/3GPP TS 24.008 and 
table 10.5.141a/3GPPTS 24.008. 



P-TMSI signature 2 lEI 



Length of P-TMSI signature 2 contents 



P-TMSI signature 2 value 



octet 1 
octet 2 
octet 3 

octet 5 



Figure 1 0.5.1 24a/3GPP TS 24.008: P-TMS/s/flfnafure 2 information element 
Table 10.5.141a/3GPP TS 24.008: P-TMS/s/flfnafure 2 information element 



P-TMSI signature 2 value is coded as octets 2 to 4 of the P-TMSI signature IE. 



10.5.5.9 Identity type 2 

The purpose of the identity type 2 information element is to specify which identity is requested. 

The identity type 2 is a type 1 information element. 

The identity type 2 information element is coded as shown in figure 10.5.125/3GPP TS 24.008 and table 10.5.142/3GPP 
TS 24.008. 
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1 



Identity type 2 
lEI 



spare 


Type of 
identity 



octet 1 



Figure 10.5.125/3GPP TS 24.008: Identity fype 2 information element 
Table 1 0.5.1 42/3GPP TS 24.008: Identity type 2 information element 



Type of identity (octet 1 ) 


Bits 




3 2 1 




1 


IMSI 


1 


IMEI 


1 1 


IMEISV 


1 


TMSI 



All other values are interpreted as IMSI by this version of the protocol. 



10.5.5.10 IMEISV request 

The purpose of the IMEISV request information element is to indicate that the IMEISV shall be included by the MS in 
the authentication and ciphering response message. 

The IMEISV request is a type 1 information element. 

The IMEISV request information element is coded as shown in figure 10.5.126/3GPP TS 24.008 and 
table 10.5.143/3GPP TS 24.008. 



1 

octet 1 

Figure 10.5.126/3GPP TS 24.008: IMEISV request information element 
Table 1 0.5.1 43/3GPP TS 24.008: /ME/S l/requesMnformation element 



IMEISV request 
IE! 



spare 


IMEISV request 
value 



IMEISV request value (octet 1) 






Bits 








3 2 1 











IMEISV not requested 






1 


IMEISV requested 






All other val 


jes are interpreted as IMEISV not requested by this 


version 


of the protocol. 



1 0.5.5.1 1 Receive N-PDU Numbers list 

The purpose of the Receive N-PDU Numbers list information element is to specify the current SNDCP Receive N-PDU 

Number values. 

The Receive N-PDU Number list is a type 4 information element with a length of 4 to 19 octets. 

The value part of a Receive N-PDU Number list information element is coded as shown in figure 10.5.127/3GPP TS 
24.008 and table 10.5.144/3GPP TS 24.008. 
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Receive N-PDU Number list lEI 



Length of Receive N-PDU Number list contents 



Receive N-PDU Number-list 



octet 1 

octet 3 
octet 4 

octet n* 



Figure 1 0.5.1 27/3GPP TS 24.008: Receive N-PDU Number list \n\ormation element 



Table 1 0.5.1 44/3GPP TS 24.008: Receive N-PDU Number iist information element 



Receive N-PDU Number -list value ::= 

{ 

< Receive N-PDU Number -list > 

< Padding bits> 

}; 

< Receive N-PDU Number-list > ::= < sapi : bit-string(4) > < Receive N-PDU 
Number-value : bit-string(8) > { < Receive N-PDU Number-list> I < null > } ; 



< nsapi > 


::= 


{0101 }; 


- NSAPI 5 


{0110}; 


- NSAPI 6 


{0111}; 


- NSAPI 7 


{ 1000 }; 


- NSAPI 8 


{ 1001 }; 


- NSAPI 9 


{ 1010}; 


- NSAPI 10 


{1011}; 


-NSAPI 11 


{ 1100}; 


- NSAPI 12 


{1101}; 


-NSAPI 13 


{1110}; 


- NSAPI 14 


{1111}; 


- NSAPI 15 



< Receive N-PDU Number-value > ::= { I 1 } (8) ; 

— Contains the binary coded representation of the receive N-PDU Number value. 

— The first bit in transmission order is the most significant bit. 

<Padding bits> ::= null I 0000; 



1 0.5.5.1 2 MS network capability 

The purpose of the MS network capability information element is to provide the network with information concerning 
aspects of the mobile station related to GPRS. The contents might affect the manner in which the network handles the 
operation of the mobile station. The MS network capability information indicates general mobile station characteristics 
and it shall therefore, except for fields explicitly indicated, be independent of the frequency band of the channel it is 
sent on. 

The MS network capability is a type 4 information element with a maximum of 10 octets length. 

The value part of a MS network capabilityinf oimation element is coded as shown in figure 10.5.128/3GPP TS 24.008 
and table 10.5.145/3GPP TS 24.008. 

NOTE: The requirements for the support of the GEA algorithms in the MS are specified in 3GPP TS 43.020 [13]. 
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MS network capability lEI 



Lengtii of IVIS networl< capability contents 



MS network capability value 



octet 1 
octet 2 
octet 3-10 



Figure 1 0.5.1 28/3GPP TS 24.008 MS network capability information element 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 508 ETSI TS 124 008 V1 0.1 0.0 (2013-04) 

Table 1 0.5.1 45/3GPP TS 24.008 MS network capability information element 



<MS network capability value part> ::= 

<GEA1 bits> 

<SM capabilities via dedicated channels: bit> 

<SM capabilities via GPRS channels: bit> 

<UCS2 support: bit> 

<SS Screening Indicator: bit string(2)> 

<SoLSA Capability : bit> 

<Revision level indicator: bit> 

<PFC feature mode: bit> 

<Extended GEA bits> 

<LCS VA capability: bit> 

<PS inter-RAT HO from GERAN to UTRAN lu mode capability: bit> 

<PS inter-RAT HO from GERAN to E-UTRAN SI mode capability: bit> 

<EMM Combined procedures Capability: bit> 

<ISR support: bit> 

<SRVCC to GERAN/UTRAN capability: bit> 

<EPC capability: bit> 

<NF capability: bit> 
<Spare bits>; 

<GEA1 bits> ::= < GEA/1 :bit>; 

<Extended GEA bits> ::= <GEA/2:bit><GEA/3:bit>< GEA/4:bit >< GEA/5:bit >< GEA/6:bit ><GEA/7:bit>; 

<Spare bits> ::= null I {<spare bit> < Spare bits >}; 

SS Screening Indicator 

defined in 3GPP TS 24.080 [24] 

1 defined in 3GPP TS 24.080 [24] 

1 defined in 3GPP TS 24.080 [24] 
1 1 defined in 3GPP TS 24.080 [24] 

SM capabilities via dedicated channels 

Mobile station does not support mobile terminated point to point SMS via CS domain 

1 Mobile station supports mobile terminated point to point SMS via CS domain 

SM capabilities via GPRS channels 

Mobile station does not support mobile terminated point to point SMS via PS domain 

1 Mobile station supports mobile terminated point to point SMS via PS domain 

UCS2 support 

This information field indicates the likely treatment by the mobile station of UCS2 encoded character strings. 

the ME has a preference for the default alphabet (defined in 3GPP TS 23.038 [8b]) 
over UCS2. 

1 the ME has no preference between the use of the default alphabet and the 
useofUCS2. 

GPRS Encryption Algorithm GEA/1 

encryption algorithm GEA/lnot available 

1 encryption algorithm GEA/1 available 

SoLSA CapabiUty 

The ME does not support SoLSA. 

1 The ME supports SoLSA. 

Revision level indicator 

used by a mobile station not supporting R99 or later versions of the protocol 
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1 used by a mobile station supporting R99 or later versions of the protocol 

PFC feature mode 

Mobile station does not support BSS packet flow procedures 

1 Mobile station does support BSS packet flow procedures 

GEA/2 

encryption algorithm GEA/2 not available 

1 encryption algorithm GEA/2 available 

GEA/3 

encryption algorithm GEA/3 not available 

1 encryption algorithm GEA/3 available 

GEA/4 

encryption algorithm GEA/4 not available 

1 encryption algorithm GEA/4 available 

GEA/5 

encryption algorithm GEA/5 not available 

1 encryption algorithm GEA/5 available 

GEA/6 

encryption algorithm GEA/6 not available 

1 encryption algorithm GEA/6 available 

GEA/7 

encryption algorithm GEA/7 not available 

1 encryption algorithm GEA/7 available 

LCS VA capability (LCS value added location request notification capability) 

This information field indicates the support of the LCS value added location request notification via PS domain as 
defined in 3GPP TS 23.271 [105]. 

location request notification via PS domain not supported 

1 location request notification via PS domain supported 

PS inter-RAT HO from GERAN to UTRAN lu mode capability 

This information field indicates the support of the PS inter-RAT HO from GERAN to UTRAN lu mode. 

PS inter-RAT HO from GERAN to UTRAN lu mode not supported 

1 PS inter-RAT HO from GERAN to UTRAN lu mode supported 

PS inter-RAT HO from GERAN to E-UTRAN SI mode capability 

This information field indicates the support of the PS inter-RAT HO from GERAN to E-UTRAN SI mode. 

PS inter-RAT HO from GERAN to E-UTRAN S 1 mode not supported 

1 PS inter-RAT HO from GERAN to E-UTRAN S 1 mode supported 

EMM Combined procedures capability 

This information field indicates the support of EMM combined procedures. 

Mobile station does not support EMM combined procedures 

1 Mobile station supports EMM combined procedures 

ISR support 

The mobile station does not support ISR. 

1 The mobile station supports ISR. 

SRVCC to GERAN/UTRAN capability 

SRVCC from UTRAN HSPA or E-UTRAN to GERAN/UTRAN not supported 

1 SRVCC from UTRAN HSPA or E-UTRAN to GERAN/UTRAN supported 

EPC capability 

This information field indicates if the MS supports access to the EPC via access networks other than GERAN or 
UTRAN. The network can use this information to decide whether to select a PDN Gateway or a GGSN. The MS shall set 
the indication to "0" if a SIM is inserted in the MS. 
EPC not supported 
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1 EPC supported 




NF capability 




This information field indicates if the MS supports the notification procedure. 


Mobile station does not 


support the notification procedure. 


1 Mobile station supports 


the notification procedure. 



1 0.5.5.1 2a MS Radio Access capability 

The purpose of the MS Radio Access capability information element is to provide the radio part of the network with 
information concerning radio aspects of the mobile station. The contents might affect the manner in which the network 
handles the operation of the mobile station. 

The MS Radio Access capability is a type 4 information element, with a maximum length of 52 octets. 

The MS Radio Access capability information element is coded as shown in figure 10.5.128a/3GPP TS 24.008 and table 
10.5.146/3GPPTS 24.008. 

For the indication of the radio access capabilities the following conditions shall apply: 

- Among the three Access Type Technologies GSM 900-P, GSM 900-E and GSM 900-R only one shall be 
present. 

Due to shared radio frequency channel numbers between GSM 1800 and GSM 1900, the mobile station should 
provide the relevant radio access capability for either GSM 1800 band OR GSM 1900 band, not both. 

The MS shall indicate its supported Access Technology Types during a single MM procedure. 

If the alternative coding by using the Additional access technologies struct is chosen by the mobile station, the 
mobile station shall indicate its radio access capability for the serving BCCH frequency band in the first included 
Access capabilities struct, if this information element is not sent in response to an Access Technologies Request 
from the network or if none of the requested Access Technology Types is supported by the MS. Otherwise, the 
mobile station shall include the radio access capabilities for the frequency bands it supports in the order of 
priority requested by the network (see 3GPP TS 44.060 [76]). 

The first Access Technology Type shall not be set to "1111". 

For error handling the following shall apply: 

- If a received Access Technology Type is unknown to the receiver, it shall ignore all the corresponding fields. 

- If within a known Access Technology Type a receiver recognizes an unknown field it shall ignore it. 

- For more details about error handling of MS radio access capability see 3GPP TS 48.018 [86]. 

NOTE: The requirements for the support of the A5 algorithms in the MS are specified in 3GPP TS 43.020 [13]. 



MS Radio Access Capability lEI 



Lengtii of IVIS Radio Access Capability contents 



IVIS RA capability value part 



octet 1 
octet 2 
octet 3-52 



Figure 1 0.5.1 28a/3GPP TS 24.008 MS Radio Access Capab/7/fy information element 
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Table 1 0.5.1 46/3GPP TS 24.008: MS Radio Access Capability \niormat\on Element 



< MS RA capability value part > ::= 

< MS RA capability value part struct > 

<spare bits>**; — may be used for future enhancements 

<MS RA capability value part struct >::= —recursive structure allows any number of Access technologies 
{ { < Access Technology Type: bit (4) > exclude 1111 

< Access capabilities : <Access capabilities struct> > } 

I { < Access Technology Type: bit (4) == 1 1 1 1 > — structure adding Access technologies with same 
capabilities 

< Length : bit (7) > — length in bits of list of Additional access technologies and spare bits 
{ 1 < Additional access technologies: < Additional access technologies struct > > } ** 
<spare bits>** } } 

{Oil <MS RA capability value part struct> } ; 

< Additional access technologies struct > ::= 

< Access Technology Type : bit (4) > 

< GMSK Power Class : bit (3) > 

< 8PSK Power Class : bit (2) > ; 

< Access capabilities struct > ::= 

< Length : bit (7) > — length in bits of Content and spare bits 
<Access capabilities : <Content» 

<spare bits>** ; — expands to the indicated length 
— may be used for future enhancements 

< Content > ::= 

< RF Power Capability : bit (3) > 
{Oil <A5 bits : <A5 bits> > } — zero means that the same values apply for parameters as in the immediately 
preceding Access capabilities field within this IE 

< ES IND : bit > 

< PS : bit > 

< VGCS : bit > 

< VBS : bit > 

{ I 1 < Multislot capability : Multislot capability struct > } — zero means that the same values for multislot 
parameters as given in an earlier Access capabilities field within this IE apply also here 

— Additions in release 99 

{ I 1 < 8PSK Power CapabiUty : bit(2) >} 

< COMPACT Interference Measurement CapabiUty : bit > 

< Revision Level Indicator : bit > 

< UMTS FDD Radio Access Technology Capability : bit > - 3G RAT 

< UMTS 3.84 Mcps TDD Radio Access Technology Capability : bit > - 3G RAT 

< CDMA 2000 Radio Access Technology Capability : bit > - 3G RAT 

— Additions in release 4 

< UMTS 1.28 Mcps TDD Radio Access Technology Capability: bit > - 3G RAT 

< GERAN Feature Package 1 : bit > 

{ I 1 < Extended DTM GPRS Multi Slot Class : bit(2) > 

< Extended DTM EGPRS Multi Slot Class : bit(2) > } 

< Modulation based multislot class support : bit > 

— Additions in release 5 

{ I 1 < High Multislot Capability : bit(2) > } 
{ I 1 < GERAN lu Mode Capabilities > } 

< GMSK Muhislot Power Profile : bit (2) > 

< 8-PSK Multislot Power Profile : bit (2) > 

— Additions in release 6 

< Multiple TBF Capability : bit > 

< Downlink Advanced Receiver Performance : bit(2) > 

< Extended RLC/MAC Control Message Segmentation CapabiUty : bit > 
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< DTM Enhancements Capability : bit > 

{ I 1 < DTM GPRS High Multi Slot Class : bit(3) > 

{ I 1 < DTM EGPRS High Multi Slot Class : bit(3) > } } 

< PS Handover CapabiUty : bit > 

■ Additions in release 7 

< DTM Handover Capability : bit > 

{ I 1 < Multislot Capability Reduction for Downlink Dual Carrier: bit (3) > 
< Downlink Dual Carrier for DTM Capability : bit> } 

< Flexible Timeslot Assignment : bit > 

< GAN PS Handover CapabiUty : bit > 

< RLC Non-persistent Mode : bit > 

< Reduced Latency CapabiUty : bit > 

< Uplink EGPRS2 : bit(2) > 

< DownUnk EGPRS2 : bit(2) > 

■ Additions in release 8 

< E-UTRA FDD support : bit > 

< E-UTRA TDD support : bit > 

< GERAN to E-UTRA support in GERAN packet transfer mode: bit(2) > 

< Priority-based reselection support : bit > 

■ Additions in release 9 

< Enhanced Flexible Timeslot Assignment : Enhanced Flexible Timeslot Assignment stmct> 

< Indication of Upper Layer PDU Start CapabiUty for RLC UM : bit > 

< EMST Capability : bit > 

< MTTI Capability : bit > 

< UTRA CSG Cells Reporting : bit > 

< E-UTRA CSG CeUs Reporting : bit > 

■ Additions in release 10 

< DTR CapabiUty : bit > 

< EMSR CapabiUty : bit > 

< Fast Downlink Frequency Switching Capability : bit > 

< TIGHTER Capability : bit(2) >; 

- error: struct too short, assume features do not exist 

- error: struct too long, ignore data and jump to next Access technology 
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Table 10.5.146/3GPP TS 24.008 (continued): MS Radio Access Capability \E 



< Multislot capability struct > ::= 

{ I 1 < HSCSD multislot class : bit (5) > } 

{ I 1 < GPRS multislot class : bit (5) > < GPRS Extended Dynamic Allocation Capability : bit > } 
{ I 1 < SMS_VALUE : bit (4) > < SM_VALUE : bit (4) > } 
-- Additions in reiease 99 

{ I 1 < ECSD multislot class : bit (5) > } 

{ I 1 < EGPRS multislot class : bit (5) > < EGPRS Extended Dynamic Allocation Capability : bit > } 

{ I 1 < DTM GPRS Multi Slot Class: bit(2)> 

<Single Slot DTIVI : bit> 

{0 I 1 <DTM EGPRS Multi Slot Class : bit(2)> } } ; 
-- error: struct too short, assume features do not exist 

< GERAN lu Mode Capabilities > ::= 

< Length : bit (4) > -- lengtii in bits of lu mode-only capabilities and spare bits 
- Additions in release 6 

< FLO lu Capability : bit > 

<spare bits>** ; -- expands to the indicated length 

-- may be used for future enhancements 

<A5 bits> ::= < A5/1 : bit> <A5/2 : bit> <A5/3 : bit> <A5/4 : bit> <A5/5 : bit> <A5/6 : bit> <A5/7 : bit>; -- bits for circuit 
mode ciphering algorithms. These fields are not used by the network and may be excluded by the IVIS. 

< Enhanced Flexible Timeslot Assignment struct > ::= 

{ I 1 < Alternative EFTA Multislot Class : bit(4) > 

< EFTA Multislot Capability Reduction for Downlink Dual Carrier: bit (3) > }; 

Access Technology Type 

This field indicates the access technology type to be associated with the following access capabilities. 

Bits 

4321 

0000 GSMP 

1 GSM E -note that GSM E covers GSI\/I P 

10 GSIVI R -note that GSM R covers GSM E and GSM P 

00 11 GSM 1800 

100 GSM 1900 

10 1 GSM 450 

110 GSM 480 

111 GSM 850 

10 GSM 750 

10 1 GSM T 380 

1010 GSMT410 

10 11 -- This value was allocated in an earlier version of the protocol and shall not be used. 

1100 GSM 710 

1101 GSMT 810 

1111 Indicates the presence of a list of Additional access technologies 
All other values are treated as unknown by the receiver. 

A MS which does not support any GSM access technology type shall set this field to '0000'. 

RF Power Capability, GMSK Power Class (3 bit field) 

This field contains the binary coding of the power class used for GMSK associated with the indicated Access 

Technology Type (see 3GPP TS 45.005 [33]). 

A MS which does not support any GSM access technology type shall set this field to '000'. 

8PSK Power Capability (2 bit field) 

If 8-PSK modulation is supported for uplink, this field indicates the radio capability for 8-PSK modulation. The 

following coding is used (see 3GPP TS 45.005 [33]): 

Bits 2 1 

Reserved 

1 Power class El 

1 Power class E2 
1 1 Power class E3 

The presence of this field also indicates 8PSK modulation capability in the uplink. 
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8PSK Power Class (2 bit field) 

This field indicates the radio capability for 8-PSK modulation. The following coding Is used (see 3GPP TS 45.005 

[33]): 

Bits 2 1 

8PSK modulation not supported for uplink 

1 Power class El 

1 Power class E2 
1 1 Power class E3 

Additional access technologies struct 

This structure contains the GIVISK Power Class and 8PSK Power Class for an additional Access Technology. All 
other capabilities for this indicated Access Technology are the same as the capabilities indicated by the preceding 
Access capabilities struct. 

A5/1 

encryption algorithm A5/1 not available 

1 encryption algorithm A5/1 available 
A5/2 

The MS shall set this bit to '0'. 

The network shall accept any received value. 

encryption algorithm A5/2 not available 

1 Not used. This value was allocated in earlier versions of the protocol. 
A5/3 

encryption algorithm A5/3 not available 

1 encryption algorithm A5/3 available 
A5/4 

encryption algorithm A5/4 not available 

1 encryption algorithm A5/4 available 
A5/5 

encryption algorithm A5/5 not available 

1 encryption algorithm A5/5 available 
A5/6 

encryption algorithm A5/6 not available 

1 encryption algorithm A5/6 available 
A5/7 

encryption algorithm A5/7 not available 

1 encryption algorithm A5/7 available 

ES IND - (Controlled early Classmark Sending) 

"controlled early Classmark Sending" option is not implemented 

1 "controlled early Classmark Sending" option is implemented 
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Table 10.5.146/3GPP TS 24.008 (concluded): MS Radio Access Capability \E 



PS - (Pseudo Synchronisation) 

PS capability not present 

1 PS capability present 

VGCS - (Voice Group Call Service) 

no VGCS capability or no notifications wanted 

1 VGCS capability and notifications wanted. 

VBS - (Voice Broadcast Service) 

no VBS capability or no notifications wanted 

1 VBS capability and notifications wanted 

HSCSD Multi Slot Class 

The Multi Slot Class field is coded as the binary representation of the multislot class defined in 3GPP TS 45.002 [32]. 

This field is not used by the network and may be excluded by the MS. 

Range 1 to 18, all other values are reserved. 

GPRS Multi Slot Class 

The GPRS Multi Slot Class field is coded as the binary representation of the multislot class defined in 3GPP TS 

45.002 [32]. 

ECSD Multi Slot Class 

The presence of this field indicates ECSD capability. Whether the MS is capable of 8-PSK modulation in uplinl< is 

indicated by the presence of 8-PSK Power Capability field. The Multi Slot Class field is coded as the binary 

representation of the multislot class defined in 3GPP TS 45.002 [32]. This field is not used by the networl< and may 

be excluded by the MS. 

Range 1 to 18, all other values are reserved. 

EGPRS Multi Slot Class 

The presence of this field indicates EGPRS capability. Whether the MS is capable of 8-PSK modulation in uplink is 

indicated by the presence of 8-PSK Power Capability field. The EGPRS Multi Slot Class field is coded as the binary 

representation of the multislot class defined in 3GPP TS 45.002 [32]. 

The same multislot capability is applicable also for EGPRS2 if supported. 

GPRS Extended Dynamic Allocation Capability 

Extended Dynamic Allocation Capability for GPRS is not implemented 

1 Extended Dynamic Allocation Capability for GPRS is implemented 

If a multislot class type 1 MS indicates in the GPRS Multi Slot Class field the support of a multislot class for which 
three or more uplink timeslots can be assigned. Extended Dynamic Allocation for GPRS shall be implemented in the 
mobile station. 

EGPRS Extended Dynamic Allocation Capability 

Extended Dynamic Allocation Capability for EGPRS and EGPRS2 (if supported) is not implemented 

1 Extended Dynamic Allocation Capability for EGPRS and EGPRS2 (if supported) is implemented 

If a multislot class type 1 MS indicates in the EGPRS Multi Slot Class field the support of a multislot class for which 
three or more uplink timeslots can be assigned, Extended Dynamic Allocation for EGPRS and EGPRS2 (if 
supported) shall be implemented in the mobile station. 

SMS_VALUE (Switch-Measure-Switch) (4 bit field) 

The SMS field indicates the time needed for the mobile station to switch from one radio channel to another, perform a 

neighbor cell power measurement, and the switch from that radio channel to another radio channel. This field is not 

used by the network and may be excluded by the MS. 

Bits 

4321 

1/4 timeslot (-144 microseconds) 

1 2/4 timeslot (-288 microseconds) 

10 3/4 timeslot (-433 microseconds) 

1111 16/4 timeslot (-2307 microseconds) 

(SM_VALUE) Switch-Measure (4 bit field) 

The SM field indicates the time needed for the mobile station to switch from one radio channel to another and 

perform a neighbour cell power measurement. This field is not used by the network and may be excluded by the MS. 

Bits 

4321 

1/4 timeslot (-144 microseconds) 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



516 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



1 2/4 timeslot (-288 microseconds) 
10 3/4 timeslot (-433 microseconds) 

1111 16/4 timeslot (-2307 microseconds) 



DTM GPRS Multi Slot Class (2 bit field) 

This field indicates the DTM GPRS multislot capabilities of the IVIS. It is coded as follows: 

Bits 

2 1 

Unused. If received, the network shall interpret this as '01 ' 

1 IVIultislot class 5 supported 

1 Multislot class 9 supported 
11 Multislot class 11 supported 

This field shall contain one of the following values if the DTM GPRS High Multi Slot Class field is present: 

Multislot class 9 if DTM GPRS High Multi Slot Glass is set to indicate Class 31/36 or Class 41 ; 

Multislot class 1 1 if DTM GPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 44. 

Single Slot DTM (1 bit field) 

This field indicates whether the MS supports single slot DTM operation (see 3GPP TS 43.055 [87]). 

Bit 

Single Slot DTM not supported 

1 Single Slot DTM supported 

An MS indicating support for Extended DTM GPRS multislot class or Extended DTM EGPRS multislot class shall 
set this bit to '1 '. The network may ignore the bit in this case. 

DTM EGPRS Multi Slot Class (2 bit field) 

This field indicates the DTM EGPRS multislot capabilities of the MS. This field shall be included only if the mobile 

station supports EGPRS DTM. This field is coded as the DTM GPRS multislot Class field. 

This field shall contain one of the following values if the DTM EGPFIS Higli Multi Slot Class field is present: 

Multislot class 9 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41 ; 

Multislot class 1 1 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 

44. 

The same multislot capability is applicable also for EGPRS2 if supported. 

COMPACT Interference Measurement Capability (1 bit field) 

COMPACT Interference Measurement Capability is not implemented 

1 COMPACT Interference Measurement Capability is implemented 

Revision Level Indicator (1 bit field) 
Bit 

The ME is Release '98 or older 

1 The ME is Release '99 onwards 

UMTS FDD Radio Access Technology Capability (1 bit field) 
Bit 

UMTS FDD not supported 

1 UMTS FDD supported 

UMTS 3.84 Mcps TDD Radio Access Technology Capability (1 bit field) 
Bit 

UMTS 3.84 Mcps TDD not supported 

1 UMTS 3.84 Mcps TDD supported 

CDMA 2000 Radio Access Technology Capability (1 bit field) 
Bit 

CDMA 2000 not supported 

1 CDMA 2000 supported 

UMTS 1 .28 Mcps TDD Radio Access Technology Capability (1 bit field) 
Bit 
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DGMSC Bit 2 1 


Bit 2 1 


00 


00 


00 


01 


00 


1 


00 


1 1 


01 


00 


01 


01 


01 


1 


01 


1 1 


1 


00 


1 


01 


1 


1 


1 


1 1 


1 1 


00 


1 1 


01 


1 1 


1 


1 1 


1 1 



UMTS 1 .28 Mcps TDD not supported 

1 UMTS 1 .28 Mcps TDD supported 

GERAN Feature Package 1 (1 bit field) 

The support of interworl<ing towards E-UTRA is indicated separately in tine "GERAN to E-UTRA support in 
GERAN packet transfer mode" field. This field indicates whether the MS supports the GERAN Feature Package 1 
(see 3GPP TS 44.060 [76]). It is coded as follows: 

GERAN feature package 1 not supported. 

1 GERAN feature package 1 supported. 

Extended DIM GPRS Multi Slot Class (2 bit field) 

This field indicates the extended DTM GPRS capabilities of the MS and shall be interpreted in conjunction with the 

DTM GPRS Multi Slot Glass field. It is coded as follows, where 'DGMSC' denotes the DTM GPRS multislot class 

field: 

ISC Bit 2 1 Bit 2 1 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Multislot class 5 supported 

Multislot class 6 supported 

Unused. If received, it shall be interpreted as '01 00' 

Unused. If received, it shall be interpreted as '01 00' 

Multislot class 9 supported 

Multislot class 10 supported 

Unused. If received, it shall be interpreted as '10 00' 

Unused. If received, it shall be interpreted as '10 00' 

Multislot class 11 supported 

Unused. If received, it shall be interpreted as '1 1 00' 

Unused. If received, it shall be interpreted as '1 1 00' 

Unused. If received, it shall be interpreted as '1 1 00' 

The presence of this field indicates that the MS supports combined fullrate and halfrate GPRS channels in the 
downlink. When this field is not present, the MS supports the multislot class indicated by the DTM GPRS Multi Slot 
C/ass field. 

If this field is included, it shall contain one of the following values if the DTM GPRS High Multi Slot Class field is 
present: 

Multislot class 1 if DTM GPRS High Multi Slot Glass is set to indicate Glass 31/36 or Class 41 ; 

Multislot class 1 1 if DTM GPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 44. 

Extended DTM EGPRS Multislot Class (2 bit field) 

This field is not considered when the DTM EGPRS Multislot Class field is not included. This field indicates the 
extended DTM EGPRS multislot capabilities of the MS and shall be interpreted in conjunction with the DTM EGPRS 
Multislot Class field. This field is coded as the Extended DTM GPRS Multislot Class field. The presence of this field 
indicates that the MS supports combined fullrate and halfrate GPRS channels in the downlink. When this field is not 
present, the MS supports the multislot class indicated by the DTM EGPRS Multi Slot Class field. 

If this field is included, it shall contain one of the following values if the DTM EGPRS High Multi Slot Class field is 
present: 

Multislot class 10 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41 ; 

Multislot class 1 1 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 

44. 

Modulation based multislot class support (1 bit field) 
Bit 

"Modulation based multislot class" not supported 

1 "Modulation based multislot class" supported 

High Multislot Capability (2 bit field) 

The High Multislot Capability is individually combined with each multislot class field sent by the MS (the possible 

multislot class fields are: GPRS multislot class, EGPRS multislot class) to extend the related multislot class to 

multislot classes 30 to 45, see 3GPP TS 45.002 [32]. The same capability is applicable also to EGPRS2 if 

supported. 

For each multislot class, the following mapping is done: 
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Bits 








2 1 


coded multislot class field 


actual multislot class 


00 


8 




30 


00 


10,23,28,29 




39 


00 


1 1 , 20, 25 




32 


00 


12,21,22,26, 


27 


33 


00 


Any other 




Multislot Class field value 


01 


8 




35 


01 


10, 19,24 




36 


01 


11,23, 28,29 




45 


01 


12,21,22,26, 


27 


38 


01 


Any other 




IVIultislot Class field value 


1 


8 




40 


1 


10, 19,24 




41 


1 


11,20, 25 




42 


1 


12,23,28,29 




44 


1 


Any other 




Multislot Class field value 


1 1 


12,21,22,26, 


27 


43 


1 1 


1 1 , 20, 25 




37 


1 1 


10, 19,24 




31 


1 1 


9, 23, 28, 29 




34 


1 1 


Any other 




Multislot Class field value 



GERAN lu Mode Capabilities 

This field indicates if the mobile station supports GERAN lu mode. Furthermore, it indicates the GERAN lu mode 
capabilities of the mobile station. The field shall be included if the mobile station supports GERAN lu mode. If the 
field is not present, the mobile station does not support GERAN lu mode. 

FLO lu Capability (1 bit field) 

If this parameter is not present, the value '0' shall be assumed by the receiver. 

FLO in GERAN lu mode not supported 

1 FLO in GERAN lu mode supported 

GMSK Multislot Power Profile (2 bit field) 

For detailed definitions, see the Mobile Station Classmark 3 information element. 

8-PSK Multislot Power Profile (2 bit field) 

For detailed definitions, see the Mobile Station Classmark 3 information element. 

Multiple TBF Capability (1 bit field) 
Bit 

Multiple TBF procedures in A/Gb mode not supported 

1 Multiple TBF procedures in A/Gb mode supported 

Downlink Advanced Receiver Performance (2 bit field) 

This field indicates Downlink Advanced Receiver Performance capabilities of the MS (see 3GPP TS 45.005 [33]). 

Bits 

2 1 

Downlink Advanced Receiver Performance not supported 

1 Downlink Advanced Receiver Performance - phase I supported 

1 Downlink Advanced Receiver Performance - phase II supported 

The value '1 1 ' shall not be used by the MS. 

If the value '11' is received by the network, it shall be interpreted as '10' . 

Extended RLC/MAC Control Message Segmentation capability (1 bit field) 
Bit 

Extended RLC/MAC control message segmentation not supported 

1 Extended RLC/MAC control message segmentation supported 

DTM Enhancements Capability (1 bit field) 

This field indicates whether the mobile station supports enhanced DTM CS establishment and enhanced DTM CS 

release or not. It is coded as follows: 

Bit 

The mobile station does not support enhanced DTM CS establishment and enhanced DTM CS release 

procedures. 

J The mobile station supports enhanced DTM CS establishment and enhanced DTM CS release procedures. 
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DTM GPRS High Mult! Slot Class (3 bit field) 

This field indicates the DTM GPRS multislot capabilities of the IVIS. It is coded as follows: 

Bit 

321 

Unused. If received, the network shall interpret this as '0 1 ' 

1 Multislot class 31 or 36 supported 

1 Multislot class 32 or 37 supported 

1 1 Multislot class 33 or 38 supported 

1 Multislot class 41 supported 
1 1 Multislot class 42 supported 
1 1 Multislot class 43 supported 
1 1 1 Multislot class 44 supported 

The presence of this field indicates that the MS supports the DTM extension to high multislot classes. When this 
field is not present, the MS supports the DTM multislot class indicated by the DTM GPRS Multi Slot Class field. 

The values '0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM GPRS multislot class 36, 37 or 38 
respectively in case the MS indicates support for one of the GPRS multislot classes 35 to 39; in all other cases 
those codepoints shall be interpreted as indicating DTM GPRS multislot class 31 , 32 or 33 respectively. 

This field shall be ignored if the High Multislot Capability field is not present. 

DTM EGPRS High Multi Slot Class (3 bit field) 

This field indicates the DTM EGPRS multislot capabilities of the MS. This field may be included only if the mobile 
station supports EGPRS DTM. This field is coded as the DTM GPRS High Multi Slot Class field. When this field is 
not present, the MS supports the DTM multislot class indicated by the DTM EGPRS Multi Slot Class field. 

The values '0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM EGPRS multislot class 36, 37 or 38 
respectively in case the MS indicates support for one of the EGPRS multislot classes 35 to 39; in all other cases 
those codepoints shall be interpreted as indicating DTM EGPRS multislot class 31 , 32 or 33 respectively. 

This field shall be ignored if the High Multislot Capability field is not present. 

The same multislot capability is applicable also for EGPRS2 if supported. 

PS Handover Capability (1 bit field) 

This field indicates whether the mobile station supports PS Handover. The PS Handover Capability applies to all 
RATs and modes indicated as supported in this information element, except for E-UTRA, where the support is 
indicated separately in the "GERAN to E-UTRA support in GERAN packet transfer mode" field. 
Bit 

The mobile station does not support PS Handover. 

1 The mobile station supports PS Handover 

DTM Handover Capability (1 bit field) 

This field indicates whether the mobile station supports DTM Handover. The DTM Handover Capability applies to all 

RATs and modes indicated as supported in this information element. It is coded as follows: 

Bit 

The mobile station does not support DTM Handover. 

1 The mobile station supports DTM Handover 

Multislot Capability Reduction for Downlink Dual Carrier (3 bit field) 

This field indicates the receive multislot capability reduction of a dual carrier capable mobile station applicable to 
EGPRS and EGPRS2 support when EFTA is not used (see 3GPP TS 45.002 [32]). This reduction applies to the 
maximum number of downlink timeslots for dual carrier operation derived from the (DTM) EGPRS (high) multislot 
class. The field is coded as follows: 

Bit 
321 

No reduction 

1 The MS supports 1 timeslot fewer than the maximum number of receive timeslots 

1 The MS supports 2 timeslots fewer than the maximum number of receive timeslots 

1 1 The MS supports 3 timeslots fewer than the maximum number of receive timeslots 

1 The MS supports 4 timeslots fewer than the maximum number of receive timeslots 
1 1 The MS supports 5 timeslots fewer than the maximum number of receive timeslots 
1 1 The MS supports 6 timeslots fewer than the maximum number of receive timeslots 
1 1 1 Reserved for future use 
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The presence of this field also indicates that the mobile station supports dual carrier in the downlink for EGPRS. 

Downlink Dual Carrier for DTM Capability (1 bit field) 

This field indicates whether the mobile station supports DTM during downlink dual carrier operation. 

Bit 

The mobile station does not support DTM during downlink dual carrier operation 

1 The mobile station supports DTI\/I during downlink dual carrier operation 

If the mobile station supports DTM during downlink dual carrier operation as indicated by this field, the Multislot 
Capability Reduction for Downlinl< Duai Carrieri\e\6 provided in the MS Radio Access Capabiiity IE is applicable to 
EGPRS DTM support as well. 

Flexible Timeslot Assignment (1 bit field) 

This field indicates whether the mobile station supports Flexible Timeslot Assignment (see 3GPP TS 45.002 [32]). 

The mobile station does not support Flexible Timeslot Assignment 

1 The mobile station supports Flexible Timeslot Assignment 

GAN PS Handover Capability (1 bit field) 

This field indicates whether or not the mobile station supports PS Handover from GERAN/UTRAN cell to a GAN 

cell. The field is coded as follows: 

Bit 

The mobile station does not support PS Handover from GERAN/UTRAN cell to a GAN cell 

1 The mobile station supports PS Handover from GERAN/UTRAN cell to a GAN cell 

RLC Non-persistent Mode Capability (1 bit field) 

This field indicates whether the mobile station supports RLC Non-persistent Mode (see 3GPP TS 44.060 [76]). 

The mobile station does not support RLC Non-persistent Mode 

1 The mobile station supports RLC Non-persistent Mode 

Reduced Latency Capability (1 bit field) 

This field indicates whether the mobile station supports Reduced TTI configurations and Fast Ack/Nack Reporting 

(see 3GPP TS 44.060 [76]) in packet transfer mode for both EGPRS and, if supported, EGPRS2. 

The mobile station does not support Reduced TTI configurations and Fast Ack/Nack Reporting 

1 The mobile station supports Reduced TTI configurations and Fast Ack/Nack Reporting 

A mobile station whose multislot class does not allow the support of Reduced TTI configurations in packet transfer 
mode due to a limited number of uplink or downlink timeslots (see 3GPP TS 45.002 [32]) shall set the Reduced 
Latency Capabiiity i\e\6 to '0'. 

Uplink EGPRS2 (2 bit field) 

This field indicates whether the mobile station supports EGPRS2-A or EGPRS2-A and EGPRS2-B in the uplink. 

Bit 
21 

The mobile station does not support either EGPRS2-A or EGPRS2-B in the uplink 

1 The mobile station supports EGPRS2-A in the uplink 

1 The mobile station supports both EGPRS2-A and EGPRS2-B in the uplink 

1 1 This value is not used in this release/version of the specifications. If received it shall be interpreted 
as '10' 

Downlink EGPRS2 (2 bit field) 

This field indicates whether the mobile station supports EGPRS2-A or EGPRS2-A and EGPRS2-B in the downlink. 

Bit 
21 
The mobile station does not support either EGPRS2-A or EGPRS2-B in the downlink 

1 The mobile station supports EGPRS2-A in the downlink 

1 The mobile station supports both EGPRS2-A and EGPRS2-B in the downlink 

1 1 This value is not used in this release/version of the specifications. If received it shall be interpreted 
as '10' 

E-UTRA FDD support (1 bit field) 
Bit 
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E-UTRA FDD not supported 

1 E-UTRA FDD supported 

E-UTRA TDD support (1 bit field) 
Bit 

E-UTRA TDD not supported 

1 E-UTRA TDD supported 

GERAN to E-UTRA support in GERAN paclcet transfer mode (2 bit field) 

This field indicates the capabilities supported by the mobile station in packet transfer mode for GERAN to E-UTRA 

interworking. If both "E-UTRA FDD support" and "E-UTRA TDD support" bits are set to '0', the bit field shall be set 

to '0 0'. If one or both of "E-UTRA FDD support" and "E-UTRA TDD support" bits are set to '1 ', the bit field may be 

any of the listed values. The bit field is coded as follows: 

Bit 

2 1 

None 

1 E-UTRAN Neighbour Cell measurements and IVIS autonomous cell reselection to E-UTRAN supported 

1 CCN towards E-UTRAN, E-UTRAN Neighbour Cell measurement reporting and Network controlled cell 

reselection to E-UTRAN supported in addition to capabilities indicated by '01' 
1 1 PS Handover to E-UTRAN supported in addition to capabilities indicated by '01' and '10' 

Priority-based reselection support (1 bit field) 

This field indicates whether the mobile station supports priority-based cell reselection. 

Priority-based cell reselection not supported 

1 Priority-based cell reselection supported 

Alternative EFTA multislot class (4 bit field) 

The presence of the Alternative EFTA multislot class field indicates that the mobile station supports Enhanced 
Flexible Timeslot Assignment, EFTA, (see 3GPP TS 45.002 [32]). This field shall be ignored if the High Multislot 
Capability field is not present. The Alternative EFTA multislot class field is used together with the (DTIVI) EGPRS 
(high) multislot class to determine the mobile stations capabilities when using Enhanced Flexible Timeslot 
Assignment, EFTA, and is coded as follows: 

Bit 

4321 

No Alternative EFTA multislot class is indicated. Use (DTM) EGPRS (high) multislot class only. 

1 Alternative EFTA multislot class 1 

10 Alternative EFTA multislot class 2 

11 Alternative EFTA multislot class 3 

100 

to 

1111 Unused. If received, these values shall be interpreted as '0000' 

EFTA Multislot Capability Reduction for Downlink Dual Carrier (3 bit field) 

This field indicates the receive multislot capability reduction of a dual carrier capable mobile station applicable to 
EGPRS and EGPRS2 support when Enhanced Flexible Timeslot Assignment is used (see 3GPP TS 45.002 [32]). 
This reduction applies to the maximum number of downlink timeslots for dual carrier operation derived from the 
Alternative EFTA Multislot Class field. The coding of this field is the same as the coding of the Multislot Capability 
Reduction for Downlink Dual Carrier field. 

This field shall be ignored if a mobile station does not support Downlink Dual Carrier. 

Indication of Upper Layer PDU Start Capability for RLC UM (1 bit field) 

This field indicates whether the mobile station supports "Indication of Upper Layer PDU Start for RLC UM" (see 

3GPP TS 44.060 [76]) for RLC unacknowledged mode of operation. The field is coded as follows: 

The mobile station does not support "Indication of Upper Layer PDU Start for RLC UM" 

1 The mobile station supports "Indication of Upper Layer PDU Start for RLC UM" 

EMST Capability (1 bit field) 

This field indicates whether the mobile station supports Enhanced Multiplexing for Single TBF (EMST) (see 

3GPP TS 44.060 [76]). 

The mobile station does not support EMST 

1 The mobile station supports EMST 

MTTI Capability (1 bit field) 
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This field indicates whetlier the mobile station supports multiple TTI (MTTI) configurations (see 

3GPP TS 44.060 [76]) 

Bit 

MTTI configurations not supported 

1 IVITTI configurations supported 

UTRA CSG Cells Reporting (1 bitfield) 

This field indicates whether the mobile station supports reporting of measurements and routing parameters (see 

3GPP TS 44.060 [76]) for UTRAN CSG cells in packet transfer mode. This capability shall apply to each UTRA 

radio access mode supported by the mobile. 

Bit 

Reporting of UTRAN CSG cells in packet transfer mode not supported 

1 Reporting of UTRAN CSG cells in packet transfer mode supported 

E-UTRA CSG Cells Reporting (1 bit field) 

This field indicates whether the mobile station supports reporting of measurements and routing parameters (see 

3GPP TS 44.060 [76]) for E-UTRAN CSG cells in packet transfer mode. This capability shall apply to each E-UTRA 

radio access mode supported by the mobile. 

Bit 

Reporting of E-UTRAN CSG cells in packet transfer mode not supported 

1 Reporting of E-UTRAN CSG cells in packet transfer mode supported 

DTR Capability (1 bit field) 

This field indicates whether the mobile station supports Dynamic Timeslot Reduction (DTR), see 

3GPP TS 44.060 [76]. 

The mobile station does not support DTR 

1 The mobile station supports DTR 

EMSR Capability (1 bit field) 

This field indicates whether the mobile station supports Enhanced Multiplexing for Single RLC Entity (EMSR), see 

3GPP TS 44.060 [76]. 

The mobile station does not support EMSR 

1 The mobile station supports EMSR 

Fast Downlink Frequency Switching Capability (1 bit field) 

This field indicates whether the mobile station supports fast downlink frequency switching between two consecutive 

TDMA frames (see 3GPP TS 45.002 [32]). 

Fast downlink frequency switching not supported 

1 Fast downlink frequency switching supported 

TIGHTER Capability (2 bit field) 

This field indicates Tightened Link Level Performance support in the MS (see 3GPP TS 45.005 [33]). The tightened 

performance applies to the traffic channels and signalling channels specified in 3GPP TS 45.005 [33]. 

Bits 

2 1 

TIGHTER not supported 

1 TIGHTER supported for speech and signalling channels only 

1 TIGHTER supported for speech and signalling channels and for GPRS and EGPRS, but not for EGPRS2 
1 1 TIGHTER supported for speech and signalling channels and for GPRS, EGPRS and EGPRS2 



10.5.5.13 Spare 

This is intentionally left spare. 

10.5.5.14 GMM cause 

The purpose of the GMM cause information element is to indicate the reason why a GMM request from the mobile 
station is rejected by the network. 

The GMM cause information element is coded as shown in figure 10.5.129/3GPP TS 24.008 and table 10.5.147/3GPP 
TS 24.008. 
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The GMM cause is a type 3 information element with 2 octets length. 



GMM cause lEI 



Cause value 



octet 1 
octet 2 



Figure 10.5.129/3GPP TS 24.008: GMM cause information element 
Table 10.5.147/3GPP TS 24.008: GMM cause information element 



Cause value (octet 2) 






Bits 
















8 7 


6 


5 


4 


3 


2 


1 



















1 





IMSI unknown in HLR 

















1 




Illegal MS 














1 







IMEI not accepted 














1 


1 





Illegal ME 














1 


1 




GPRS services not allowed 











1 











GPRS services and non-GPRS services not 
allowed 





















MS identity cannot be derived by the network 
















1 





Implicitly detached 
















1 




PLMN not allowed 













1 








Location Area not allowed 













1 







Roaming not allowed in this location area 













1 


1 





GPRS services not allowed in this PLMN 













1 


1 




No Suitable Cells In Location Area 








1 














MSC temporarily not reachable 








1 













Network failure 








1 





1 








MAC failure 








1 





1 







Synch failure 








1 





1 


1 





Congestion 








1 





1 


1 




GSM authentication unacceptable 








1 


1 










Not authorized for this CSG 










1 











No PDP context activated 







1 














} 






to 








} retry upon entry into a new cell 







1 


1 


1 


1 




} 


1 





1 


1 


1 


1 




Semantically incorrect message 


1 



















Invalid mandatory information 


1 


















Message type non-existent or not implemented 


1 













1 





Message type not compatible with the protocol 
state 


1 













1 




Information element non-existent or not 
implemented 


1 










1 








Conditional IE error 


1 










1 







Message not compatible with the protocol state 


1 







1 


1 


1 




Protocol error, unspecified 


Any other value received by the mobile station shall be treated as 0110 11 1 1 , "Protocol 


error, 


unspecifiec 


i". Any other value received by the network shall be treated as 01 1 


1111, 


"Protocol erro 


', unspecified' 




NOTE 




The listed reject cause 


values are defined in annex G. 



1 0.5.5.1 5 Routing area identification 

The purpose of the routing area identification information element is to provide an unambiguous identification of 
routing areas within the GPRS coverage area. 

The routing area identification is a type 3 information element with 7 octets length. 
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The routing area identification information element is coded as shown in figure 10.5.130/3GPP TS 24.008 and 
table 10.5.148/3GPP TS 24.008. 



Routing Area Identification lEI 


octet 1 


MCC digit 2 


MCC digit 1 


octet 2 


MNCdigitS 


IVICC digit 3 


octet 3 


IVINCdigit2 


IVINC digit 1 


octet 4 


LAC 


octet 5 


LAC cont'd 


octet 6 


RAC 


octet 7 



Figure 1 0.5.1 30/3GPP TS 24.008: Routing area identification information element 
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Table 1 0.5.1 48/3GPP TS 24.008: Routing area identification information element 



MCC, Mobile country code (octet 2 and 3) 

The MCC field is coded as in ITU-T Rec. E212, Annex A. 

If the RAI is deleted, the MCC and MNC shall take the value from the deleted RAI. 

In abnormal cases, the MCC stored in the mobile station can contain elements not in the set {0, 1 ... 9}. In such 
cases the mobile station should transmit the stored values using full hexadecimal encoding. When receiving such 
an MCC, the network shall treat the RAI as deleted. 

MNC, Mobile network code (octet 3 bits 5 to 8, octet 4) 

The coding of this field is the responsibility of each administration but BCD coding shall be used. The MNC shall 
consist of 2 or 3 digits. For PCS 1900 for NA, Federal regulation mandates that a 3-digit MNC shall be used. 
However a network operator may decide to use only two digits in the MNC in the RAI over the radio interface. In 
this case, bits 5 to 8 of octet 3 shall be coded as "1111 ". Mobile equipment shall accept RAI coded in such a way. 

NOTE 1 : In earlier versions of this protocol, the possibility to use a one digit MNC in RAI was provided on the 
radio interface. However as this was not used this possibility has been deleted. 

NOTE 2: In earlier versions of this protocol, bits 5 to 8 of octet 3 were coded as "1111 ". Mobile equipment 
compliant with these earlier versions of the protocol may be unable to understand the 3-digit MNC 
format of the RAI, and therefore unable to register on a network broadcasting the RAI in this format. 

In abnormal cases, the MNC stored in the mobile station can have: 

- digit 1 or 2 not in the set {0, 1 ... 9}, or 

- digit 3 not in the set {0, 1 ... 9, F} hex. 

In such cases the mobile station shall transmit the stored values using full hexadecimal encoding. When 
receiving such an MNC, the network shall treat the RAI as deleted. 

The same handling shall apply for the network, if a 3-digit MNC is sent by the mobile station to a network using 
only a 2-digit MNC. 

LAC, Location area code (octet 5 and 6) 

In the LAC field bit 8 of octet 5 is the most significant bit and bit 1 of octet 6 the least significant bit. 

The coding of the location area code is the responsibility of each administration except that two values are used 

to mark the LAC, and hence the RAI, as deleted. Coding using full hexadecimal representation may be used. The 

location area code consists of 2 octets. 

If a RAI has to be deleted then all bits of the location area code shall be set to one with the exception of the least 

significant bit which shall be set to zero. If a SIM/USIM is inserted in a Mobile Equipment with the location area 

code containing all zeros, then the Mobile Equipment shall recognise this LAC as part of a deleted RAI. 

RAC, Routing area code (octet 7) 

In the RAC field bit 8 of octet 7 is the most significant. The coding of the routing area code is the responsibility of 
each administration. Coding using full hexadecimal representation may be used. The routing area code consists 
of 1 octet. 



1 0.5.5.1 5a Routing area identification 2 

The purpose of the Routing area identification 2 information element is to provide an unambiguous identification of 
routing areas within the GPRS coverage area. 

The Routing area identification 2 is a type 4 information element with a length of 8 octets. 

The Routing area identification 2 information element is coded as shown in figure 10.5.130a/3GPP TS 24.008 and 
table 10.5.148a/3GPPTS 24.008. 
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Routing area identification 2 lEI 



Lengtii of routing area identification 2 I El 



Routing area identification 2 value 



octet 1 
octet 2 
octet 3 

octet 8 



Figure 1 0.5.1 30a/3GPP TS 24.008: Routing area identification 2 information element 
Table 1 0.5.1 48a/3GPP TS 24.008: Routing area identification 2 information element 



Routing area identification 2 value (octet 3 to 8) 

The routing area identification 2 value is coded as octet 2 to 7 of the Routing area identification information 
element. 



10.5.5.16 Spare 

This is intentionally left spare. 

10.5.5.17 Update result 

The purpose of the update result information element is to specify the result of the associated updating procedure. 

The update result is a type 1 information element. 

The update result information element is coded as shown in figure 10.5.131/3GPP TS 24.008 and table 10.5.149/3GPP 
TS 24.008. 



8 



Update result 
IE! 


FOP 


Update result 
value 



octet 1 

Figure 10.5.131/3GPP TS 24.008: Update resu/f information element 
Table 1 0.5.1 49/3GPP TS 24.008: Update result information element 



Update result value (octet 1 ) 
Bits 

3 2 1 



1 

1 
1 1 



RA updated 

combined RA/LA updated 

RA updated and ISR activated 

combined RA/LA updated and ISR activated 



All other values are reserved. 

Follow-on proceed (octet 1 , bit 4) 

Bit 

4 

Follow-on proceed 

1 No follow-on proceed 

Follow-on proceed is applicable only in lu mode. This indication shall be ignored if 
received in A/Gb mode. 
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10.5.5.18 Update type 

The purpose of the update type information element is to specify the area the updating procedure is associated with. 

The update type is a type 1 information element. 

The update type information element is coded as shown in figure 10.5.132/3GPP TS 24.008 and table 10.5.150/3GPP 
TS 24.008. 



Update type 
lEI 


FOR 


Update type 
value 



1 

octet 1 

Figure 1 0.5.1 32/3GPP TS 24.008: Update type information element 
Table 1 0.5.1 50/3GPP TS 24.008: Update type information element 



Update type value (octet 1 , bit 1 to 3) 
Bits 



3 2 1 



1 

1 

1 1 



RA updating 

combined RA/LA updating 

combined RA/LA updating with I MS I attach 

Periodic updating 



All other values are reserved. 

Follow-on request (octet 1 , bit 4) 
Bit 



No follow-on request pending 
Follow-on request pending 



Follow-on request pending is applicable only in lu mode. 



1 0.5.5.1 9 A&C reference number 

The purpose of the A<4C reference number information element is to indicate to the network in the 
AUTHENTICATION AND CIPHERING RESPONSE message which AUTHENTICATION AND CIPHERING 
REQUEST message the MS is replying to. 

The A&C reference number is a type 1 information element. 

The A&C reference number information element is coded as shown in figure 10.5.134/3GPP TS 24.008 and 
table 10.5.152/3GPP TS 24.008. 



octet 1 



8 7 6 5 


4 3 2 1 


A&C reference number 
lEI 


A&C reference number 
value 



Figure 1 0.5.1 34/3GPP TS 24.008: A&C reference number information element 
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Table 1 0.5.1 52/3GPP TS 24.008: A&C reference number information element 



A&C reference number value (octet 1) 
Unformatted 4 bit field 



10.5.5.20 Service type 

The purpose of the service type information element is to specify the purpose of the Service request procedure. 

The service type is a type 1 information element. 

The service type information element is coded as shown in figure 10.5.135/3GPP TS 24.008 and table 10.5.153a/3GPP 
TS 24.008. 



Service type 
lEI 



spare 


Service type 



1 

octet 1 

Figure 10.5.135/3GPP TS 24.008: Service type information element 
Table 1 0.5.1 53a/3GPP TS 24.008: Service type information element 



Service type value (octet 1 ) 



Bits 

3 2 1 



1 

1 

1 1 

1 



Signalling 

Data 

Paging Response 

I\/1BMS IVIulticast Service Reception 

MBMS Broadcast Service Reception 



All other values are reserved. 



10.5.5.21 Cell Notification 

The purpose of the Cell Notification information element is to indicate that the Cell Notification is supported by the 
network and shall be then used by MS. 

The Cell Notification information element is coded as shown in figure 10.5.135a/3GPP TS 24.008. 

The Cell Notification is a type 2 information element. 



Cell Notification IE! 



octet 1 



Figure 10.5.135a/3GPPTS 24.008: Cell Notification information element 
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1 0.5.5.22 PS LCS Capability 

The purpose of the PS LCS Capability element is to indicate the positioning methods and additional positioning 
capabilities supported by the MS for the provision of location services (LCS) via the PS domain in Gb-mode. 

The PS LCS Capability is a type 4 information element with a length of 3 octets. 

The PS LCS Capability element is coded as shown in figure 10.5.135b/3GPP TS 24.008 and table 10.5.153b/3GPP TS 
24.008. 



PS LCS Capability lEI 



Lengtin of PS LCS Capability contents 



Spare 



APC OTD- OTD- GPS- GPS- GPS- 
A B A B C 



octet 1 
octet 2 
octet 3 



Figure 10.5.135b/3GPP TS 24.008: PS LCS Capability information element 
Table 10.5.153b/3GPP TS 24.008 PS LCS Capabiiity information element 



PS LCS Capability \/a\ue (octet 3, bit 1 to 5) 

APC (Additional Positioning Capabilities) 
Bite 

Additional Positioning Capabilities which can be retrieved by RRLP are not supported 

1 Additional Positioning Capabilities which can be retrieved by RRLP are supported 

OTD-A (MS assisted E-OTD) 
Bits 

IVIS assisted E-OTD not supported 

1 MS assisted E-OTD supported 

OTD-B (MS based E-OTD) 
Bit 4 

MS based E-OTD not supported 

1 MS based E-OTD supported 

GPS-A (MS assisted GPS) 
Bits 

MS assisted GPS not supported 

1 MS assisted GPS supported 

GPS-B (MS based GPS) 
Bit 2 

MS based GPS not supported 

1 MS based GPS supported 

GPS-C (Conventional GPS) 
Bit1 

Conventional GPS not supported 

1 Conventional GPS supported 

Octet 3, bits 8, 7, 6 are spare and shall be coded all 0. 
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1 0.5.5.23 Network feature support 

The purpose of the network feature support information element is to indicate whether certain features are supported by 
the network. If this IE is not included then the respective features are not supported. 

The network feature support is a type 1 information element. 

The network feature support information element is coded as shown in figure 10.5.135c/3GPP TS 24.008 and 
table 10.5.153C/3GPPTS 24.008. 



1 

octet 1 

Figure 1 0.5.1 35c/3GPP TS 24.008: Network feature support information element 
Table 1 0.5.1 53c/3GPP TS 24.008: Network feature support information element 



Network feature support 
lEI 


LCS- 
MOLR 


MBMS 


IMS 
VoPS 


EMC 
BS 



Network feature support value (octet 1 , bit 1 to 4) 




LCS-MOLR (1 bit field) 




Bit 
4 








1 


LCS-MOLR via PS domain not supported 
LCS-MOLR via PS domain supported 




MBMS (1 bit field) 




Bit 
3 








1 


MBMS not supported 
MBMS supported 




IMS 


voice over PS session indicator (IMS VoPS) (1 bit field) 




Bit 
2 








1 


IMS voice over PS session in lu mode and A/Gb mode not supported 
IMS voice over PS session supported in lu mode, but not supported in 
A/Gb mode 


Emergency bearer services indicator (EMC BS) (1 bit field) 




Bit 

1 







1 


Emergency bearer services in lu mode and A/Gb mode not supported 
Emergency bearer services supported in lu mode, but not supported in 
A/Gb mode 



10.5.5.24 Inter RAT information container 

The purpose of the Inter RAT information container information element is to supply the network with lu mode related 
information that needs to be transferred at PS inter-system handover to lu mode (see 3GPP TS 43. 129 [113]). 

The Inter RAT information container information element is coded as shown in figure 10.5.150/3GPP TS 24.008. 

The Inter RAT information container information element is a type 4 information element with a minimum length of 3 
octets and a maximum length of 250 octets. 

The Inter RAT information container contains: 
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predefined configuration status information; 

mobile station security information to be used after handover to lu mode, which includes the START-PS value 
that is stored by the MS at handover from lu mode to A/Gb mode (see 3GPP TS 33.102 [5a]); and/or 

the specific lu mode radio capabilities of the mobile station, i.e. UE RAC (see 3GPP TS 25.331 [23c]). 



Inter RAT information container lEI 



Length of inter RAT information container 



Inter RAT information container value part 



octet 1 

octet 2 

octet 3-250 



Figure 10.5.150/3GPP TS 24.008: Inter RAT information confa/ner information element 

The value part of the Inter RAT information container information element is the INTER RAT HANDOVER INFO as 
defined in 3GPP TS 25.331 [23c]. If this field includes padding bits, they are defined in 3GPP TS 25.331 [23c]. 

10.5.5.25 Requested MS information 

The purpose of the Requested MS information information element is to indicate whether certain feature-related 
information is requested from the MS by the network. If this IE is not included then no information is requested. 

The, Requested MS information information element is coded as shown in figure 10.5.151/3GPP TS 24.008 and 
table 10.5.166/3GPP TS 24.008. 

The Requested MS information is a type 1 information element. 



8 7 6 5 


4 


3 


2 1 


Requested IVIS information 
lEI 


l-RAT 


I-RAT2 



Spare 



octet 1 



Figure 10.5.151/3GPP TS 24.008: Requested IVIS information information element 
Table 1 0.5.1 66/3GPP TS 24.008: Requested MS information information element 



Requested MS information value (octet 1 , bit 1 to 4) 
l-RAT (1 bit field) 



Bit 
4 

1 



Inter RAT information container IE not requested 
Inter RAT information container IE requested 



I-RAT2 (1 bit field) 
Bit 
3 

E-UTRAN inter RAT information container IE not requested 
J\ E-UTRAN inter RAT information container IE requested 



1 0.5.5.26 UE network capability 

See subclause 9.9.3.x in 3GPP TS 24.301 [120]. 
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10.5.5.27 E-UTRAN inter RAT information container 

The purpose of the E-UTRAN inter RAT information container information element is to supply the network with E- 
UTRAN related information that needs to be transferred at Inter-RAT PS handover to E-UTRAN (see 
3GPPTS 23.401 [122]). 

The E-UTRAN inter RAT information container information element is coded as shown in figure 
10.5. 151/3GPPTS 24.008. 

The E-UTRAN inter RAT information container information element is a type 4 information element with a minimum 
length of 3 octets and an upper length limit of 257 octets. 



8 



1 



E-UTRAN Inter RAT information container lEI 



Lengtii of E-UTRAN Inter RAT information container 
E-UTRAN Inter RAT information container value part 



octet 1 

octet 2 

octet 3-257 



Figure 10.5.151/3GPP TS 24.008: E-UTRAN inter RAT information conte/ner information element 

The value part of the E-UTRAN inter RAT information container information element is formatted and coded according 
to the UE-EUTRA-Capability IE defined in 3GPP TS 36.331 [129]. 

10.5.5.28 Voice domain preference and UE's usage setting 

The purpose of the Voice domain preference and UE's usage setting information element is to provide the network with 
the UE's usage setting and the voice domain preference for E-UTRAN. The network uses the UE's usage setting and the 
voice domain preference for E-UTRAN only to select the RFSP index. 

The UE's usage setting bit indicates the value configured on the ME as defined in 3GPP TS 23.221 [131]. 

The voice domain preference for E-UTRAN bit indicates the value configured on the ME of the Voice domain 
preference for E-UTRAN as defined in 3GPP TS 24.167 [134]. 

The Voice domain preference and UE's usage setting information element is coded as shown in 
figure 10.5.151A/3GPP TS 24.008 and table 10.5.1 66 A/3GPP TS 24.008. 



8 


7 


6 


5 


4 


3 


2 1 


Voice domain preference and UE's usage setting lEI 


Length of Voice domain preference and UE's usage setting contents 



Spare 



Spare 



Spare 



Spare 



Spare 


UE's 
usage 
setting 


Voice domain 

preference for 

E-UTRAN 



octet 1 
octet 2 
octet 3 



Figure 10.5.151 A/3GPP TS 24.008: Voice domain preference and UE's usage setting information 

element 
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Table 1 0.5.1 66A/3GPP TS 24.008: Voice domain preference and UE's usage setting information 

element 



Voice domain preference and UE's usage setting value (octet 3, bit 1 to 3) 
UE's usage setting (1 bit field) 



Bit 
3 

1 



Voice centric 
Data centric 



Voice domain preference for E-UTRAN (2 bit field) 



Bit 

2 1 



1 

1 

1 1 



CS Voice only 

IIVIS PS Voice only 

CS voice preferred, IIVIS PS Voice as secondary 

IIVIS PS voice preferred, CS Voice as secondary 



MS not supporting IMS voice shall indicate "CS Voice only". 
MS only supporting IMS voice shall indicate "IMS PS Voice only" 



10.5.5.29 P-TMSItype 

The purpose of the P-TMSI type information element is to indicate whether the P-TMSI included in the same message 
in an information element of type mobile identity, or the P-TMSI used by the MS to derive a foreign TLLl (see 
subclause 4.7.1.4.1) represents a native P-TMSI or a mapped P-TMSI. 

The P-TMSI type information element information element is coded as shown in figure 10.5.5.29.1 and 
table 10.5.5.29.1. 

The P-TMSI type is a type 1 information element. 



P-TMSI type lEI 



spare 


P- 
TMSI 
type 



octet 1 



Figure 10.5.5.29.1: P-TIVISI type information element 
Table 10.5.5.29.1: P-TIVISI type information element 



P-TMSI type (octet 1) 

Bit 

1 

Native P-TMSI 

1 Mapped P-TMSI 

Bits 2 to 4 of octet 1 are spare and shall be coded as zero. 



10.5.5.30 Location Area Identification 2 

The purpose of the Location Area Identification 2 information element is to provide an unambiguous identification of 
location areas within the area covered by the 3GPP system. 

The Location Area Identification 2 information element is coded as shown in figure 10.5.5.30/3GPP TS 24.008 and 
table 10.5.5.30/3GPPTS 24.008. 
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The Location Area Identification 2 is a type 4 information element with 7 octets length. 
8 7 6 5 4 3 2 1 



Location Area Identification 2 lEI 



Lengtii of Location Area Identification 2 contents 



Location Area Identification 2 value 



octet 1 
octet 2 
octet 3 



octet 7 

Figure 10.5.5.30/3GPP TS 24.008: Location Area Identification 2 information element 

Table 10.5.5.30/3GPP TS 24.008: Location Area Identification 2 information element 



Location Area Identification 2 value (octet 3 to 7) 

The Location Area Identification 2 value is coded as octet 2 to 6 of the Location Area Identification information 
element. 



1 0.5.6 Session management information elements 
10.5.6.1 Access point name 

The purpose of the Access point name information element is to identify the packet data network to which the GPRS 
user wishes to connect and to notify the access point of the packet data network that wishes to connect to the MS. 

The Access point name is a label or a fully qualified domain name according to DNS naming conventions (see 
3GPPTS 23.003 [10]). 

The Access point name is a type 4 information element with a minimum length of 3 octets and a maximum length of 
102 octets. 

The Access point name information element is coded as shown in figure 10.5. 152/3GPP TS 24.008. 



Access point name lEI 



Length of access point name contents 



Access point name value 



octet 1 
octet 2 
octet 3 



octet n* 

Figure 10.5.152/3GPP TS 24.008: Access point name information element 

The value part is defined in 3GPP TS 23.003 [10]. 

1 0.5.6.2 Network service access point identifier 

The purpose of the Network service access point identifier information element is to identify the service access point 
that is used for the GPRS data transfer at layer 3. 

The Network service access point identifier is a type 3 information element with a length of 2 octets. 

The value part of a Network service access point identifier information element is coded as shown in 
figure 10.5.153/3GPP TS 24.008 and table 10.5.167/3GPP TS 24.008. 
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8 


7 6 


5 


4 


3 2 


1 


NSAPI lEI 






Spare 





NSAPI 
value 



octet 1 
octet 2 



Figure 10.5.153/3GPP TS 24.008: Network service access point identifier information element 
Table 1 0.5.1 67/3GPP TS 24.008: Network service access point identifier information element 



NSAPI value (octet 2) 


Bits 








4 3 


2 















reserved 










reserved 





1 





reserved 





1 




reserved 


1 








reserved 


1 







NSAPI 5 


1 


1 





NSAPI 6 


1 


1 




NSAPI 7 


1 








NSAPI 8 


1 







NSAPI 9 


1 


1 





NSAPI 10 


1 


1 




NSAPI 11 


1 1 








NSAPI 12 


1 1 







NSAPI 13 


1 1 


1 





NSAPI 14 


1 1 


1 




NSAPI 15 



10.5.6.3 Protocol configuration options 

The purpose of the protocol configuration options information element is to: 

transfer external network protocol options associated with a PDP context activation, and 

transfer additional (protocol) data (e.g. configuration parameters, error codes or messages/events) associated 
with an external protocol or an application. 

The protocol configuration options is a type 4 information element with a minimum length of 3 octets and a maximum 
length of 253 octets. 

i:\\e protocol configuration options information element is coded as shown in figure 10.5.136/3GPP TS 24.008 and 
table 10.5.154/3GPP TS 24.008. 
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Protocol configuration options lEI 


octet 1 


Length of protocol config. options contents 


octet 2 


1 
ext 



Spare 


Configuration 
protocol 


octet 3 


Protocol ID 1 


octet 4 
octet 5 


Length of protocol ID 1 contents 


octet 6 


Protocol ID 1 contents 


octet 7 
octet m 


Protocol ID 2 


octet m+1 
octet m+2 


Length of protocol ID 2 contents 


octet m+3 


Protocol ID 2 contents 


octet m+4 
octet n 




octet n+1 
octet u 


Protocol ID n-1 


octet u+1 
octet u+2 


Length of protocol ID n-1 contents 


octet u+3 


Protocol ID n-1 contents 


octet u+4 
octet V 


Protocol ID n 


octet v+1 
octet v+2 


Length of protocol ID n contents 


octet v+3 


Protocol ID n contents 


octet v+4 
octet w 


Container ID 1 


octet w+1 
octet w+2 


Length of container ID 1 contents 


octet w+3 


Container ID 1 contents 


octet w+4 
octet X 




octet x+1 
octet y 


Container ID n 


octet y+1 
octet y+2 


Length of container ID n contents 


octet y+3 


Container ID n contents 


octet y+4 
octet z 



Figure 10.5.136/3GPP TS 24.008: Protocol configuration options information element 
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Table 1 0.5.1 54/3GPP TS 24.008: Protocol configuration options information element 



Configuration protocol (octet 3) 

Bits 

321 

PPP for use with IP PDP type or IP PDN type (see 3GPP TS 24.301 [120]) 

All other values are interpreted as PPP in this version of the protocol. 
After octet 3, i.e. from octet 4 to octet z, two logical lists are defined: 

- the Configuration protocol options list (octets 4 to w), and 

- the Additional parameters list (octets w+1 to z). 

Configuration protocol options list (octets 4 to w) 

The configuration protocol options list contains a variable number of logical units, 
they may occur in an arbitrary order within the configuration protocol options list. 

Each unit is of variable length and consists of a: 

- protocol identifier (2 octets); 

- the length of the protocol identifier contents of the unit (1 octet); and 

- the protocol identifier contents itself (n octets). 

The protocol identifier f\e\6 contains the hexadecimal coding of the configuration 
protocol identifier. Bit 8 of the first octet of the protocol identifier i\e\6 contains the 
most significant bit and bit 1 of the second octet of the protocol identifier f\e\6 
contains the least significant bit. 

If the configuration protocol options //sf contains a protocol identifier that is not 
supported by the receiving entity the corresponding unit shall be discarded. 

The lengtti of the protocol identifier contents field contains the binary coded 
representation of the length of the protocol identifier contents field of a unit. The first 
bit in transmission order is the most significant bit. 

The protocol identifier contents field of each unit contains information specific to the 
configuration protocol specified by the protocol identifier 

At least the following protocol identifiers (as defined in RFC 3232 [103]) shall be 
supported in this version of the protocol: 

- C021H(LCP); 

- C023H (PAP); 

- C223H (CHAP); and 

- 8021H(IPCP). 

The support of other protocol identifiers is implementation dependent and outside 
the scope of the present document. 

The protocol identifier contents field of each unit corresponds to a "Packet" as 
defined in RFC 1661 [102] that is stripped off the "Protocol" and the "Padding" 
octets. 

The detailed coding of the protocol identifier contents field is specified in the RFC 
that is associated with the protocol identifier of that unit. 

Additional parameters list (octets w+1 to z) 

The additional parameters //sf is included when special parameters and/or requests 
(associated with a PDP context) need to be transferred between the IVIS and the 
network. These parameters and/or requests are not related to a specific 
configuration protocol (e.g. PPP), and therefore are not encoded as the "Packets" 
contained in the configuration protocol options list 

The additional parameters //sf contains a list of special parameters, each one in a 
separate container. The type of the parameter carried in a container is identified by 
a specific container identifier In this version of the protocol, the following container 
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identifiers are specified: 
MS to networl< direction: 

- 0001 H (P-CSCF IPv6 Address Request); 

- 0002H (IM CN Subsystem Signaling Flag); 

- 0003H (DNS Server IPv6 Address Request); 

- 0004H (Not Supported); 

- 0005H (MS Support of Network Requested Bearer Control indicator); 

- 0006H (Reserved); 

- 0007H (DSMIPv6 Home Agent Address Request; 

- 0008H (DSMIPv6 Home Network Prefix Request); 

- 0009H (DSMIPv6 IPv4 Home Agent Address Request); 

- OOOAH (IP address allocation via NAS signalling); 

- OOOBH (IPv4 address allocation via DHCPv4); 

- OOOCH (P-CSCF IPv4 Address Request); 

- OOODH (DNS Server IPv4 Address Request); 

- OOOEH (MSISDN Request); 

- OOOFH (IFOM-Support-Request); 

- 001 OH (IPv4 Link MTU Request); and 

- FFOOH to FFFFH reserved for operator specific use. 

Network to MS direction: 

- 0001 H (P-CSCF IPv6 Address); 

- 0002H (IM CN Subsystem Signaling Flag); 

- 0003H (DNS Server IPv6 Address); 

- 0004H (Policy Control rejection code); 

- 0005H (Selected Bearer Control Mode; 

- 0006H (Reserved); 

- 0007H (DSMIPv6 Home Agent Address) ; 

- 0008H (DSMIPv6 Home Network Prefix); 

- 0009H (DSMIPv6 IPv4 Home Agent Address); 

- OOOAH (Reserved); 

- OOOBH (Reserved); 

- OOOCH (P-CSCF IPv4 Address); 

- OOODH (DNS Server IPv4 Address); 

- OOOEH (MSISDN); 

- OOOFH (IFOM-Support); 
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0010H {IPv4 Link MTU); and 

FFOOH to FFFFH reserved for operator specific use. 



If the additional parameters //sf contains a container identifier that is not supported 
by the receiving entity the corresponding unit shall be discarded. 

The container identifier i\e\6 is encoded as the protocol identifier i\e\6 and the iengtii 
of container identifier contents field is encoded as the Iengtii of ttie protocol identifier 
contents f\e\6. 

When the container identifier \n6\cates P-CSCF IPv6 Address Request, DNS Server 
IPv6 Address Request, or MSISDN Request, the container identifier contents field is 
empty and the length of container identifier contents indicates a length equal to 
zero. If the container identifier contents f\e\6 is not empty, it shall be ignored. 

When the container identifier \n6\cates IM CN Subsystem Signaling Flag (see 3GPP 
TS 24.229 [95]), the container identifier contents i\e\6 is empty and the length of 
container identifier contents indicates a length equal to zero. If the container 
identifier contents field is not empty, it shall be ignored. In Network to MS direction 
this information may be used by the MS to indicate to the user whether the 
requested dedicated signalling PDP context was successfully established. 

When the container identifier \n6\cates P-CSCF IPv6 Address, the container 
identifier contents i\e\6 contains one IPv6 address corresponding to a P-CSCF 
address (see 3GPP TS 24.229 [95]). This IPv6 address is encoded as an 128-bit 
address according to RFC 3513 [99]. When there is need to include more than one 
P-CSCF address, then more logical units with confa/ne/'/c/enf/T/er indicating P-CSCF 
Address are used. 

When the container identifier mdicates DNS Server IPv6 Address, the container 
identifier contents field contains one IPv6 DNS server address (see 3GPP TS 
27.060 [36a]). This IPv6 address is encoded as an 128-bit address according to 
RFC 3513 [99]. When there is need to include more than one DNS server address, 
then more logical units with container identifier indicating DNS Server Address are 
used. 

When the container identifier \n6\ca\es Policy Control rejection code, the container 
identifier contents field contains a Go interface related cause code from the GGSN 
to the MS (see 3GPP TS 29.207 [100]). The length of container identifier contents 
indicates a length equal to one. If the container identifier contents i\e\6 is empty or 
its actual length is greater than one octect, then it shall be ignored by the receiver. 

When the container identifier \n6\cates MS Support of Network Requested Bearer 
Control indicator, the container identifier contents f\e\6 is empty and the length of 
container identifier contents indicates a length equal to zero. If the container 
identifier contents field is not empty, it shall be ignored. 

When the container identifier \n6\cates Selected Bearer Control Mode, the container 
identifier contents field contains the selected bearer control mode, where '01 H' 
indicates that 'MS only' mode has been selected and '02H' indicates that 'MS/NW' 
mode has been selected. The length of container identifier contents indicates a 
length equal to one. If the container identifier contents i\e\6 is empty or its actual 
length is greater than one octect, then it shall be ignored by the receiver. 

When the container identifier \n6\cates DSMIPv6 Home Agent Address Request, the 
container identifier contents field is empty and the length of container identifier 
contents indicates a length equal to zero. If the container identifier contents field is 
not empty, it shall be ignored. 

When the container identifier \n6\ca\es DSMIPv6 Home Network Prefix Request, the 
container identifier contents f\e\6 is empty and the length of container identifier 
contents indicates a length equal to zero. If the container identifier contents field is 
not empty, it shall be ignored. 

When the container identifier \n6\cates DSMIPv6 IPv4 Home Agent Address 
Request, the container identifier contents i\e\6 is empty and the length of container 
identifier contents indicates a length equal to zero. If the container identifier contents 
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field is not empty, it shall be ignored. 

When the container identifier \r\6\cates DSMIPv6 Home Agent Address, the 
container identifier contents field contains one IPv6 address corresponding to a 
DSIVIiPve HA address (see 3GPP TS 24.303 [124] and 3GPP TS 24.327 [125]). 
This IPv6 address is encoded as an 128-bit address according to 
IETF RFC 3513 [99]. 

When the container identifier \n6\cates DSMIPv6 Home Network Prefix, the 
container identifier contents f\e\6 contains one IPv6 Home Network Prefix (see 
3GPP TS 24.303 [124] and 3GPP TS 24.327 [125]). This IPv6 prefix is encoded as 
an IPv6 address according to RFC 3513 [99] followed by 8 bits which specifies the 
prefix length. 

When the container identifier \r\6\cates DSMIPv6 IPv4 Home Agent Address, the 
container identifier contents field contains one IPv4 address corresponding to a 
DSI\/IIPv6 IPv4 Home Agent address (see 3GPP TS 24.303 [124] and 
3GPPTS 24.327 [125]). 

When the container identifier \r\6\cates P-GSGF IPv4 Address Request, the 
container identifier contents field is empty and the lengtli of container identifier 
contents indicates a length equal to zero. If the container identifier contents field is 
not empty, it shall be ignored. 

When the container identifier \r\6\cates DNS Server IPv4 Address Request, the 
container identifier contents field is empty and the lengtfi of container identifier 
contents indicates a length equal to zero. If the container identifier contents field is 
not empty, it shall be ignored. 

When the container identifier \r\6\cates P-GSGF IPv4 Address, the container 
identifier contents i\e\6 contains one IPv4 address corresponding to the P-GSGF 
address to be used. 

When the container identifier \r\6\caies DNS Server IPv4 Address, the container 
identifier contents field contains one IPv4 address corresponding to the DNS server 
address to be used. 

P-GSGF IPv4 Address Request, P-GSGF IPv4 Address, DNS Server IPv4 Address 
Request and DNS Server IPv4 Address are applicable only in SI -mode. 

When the container identifier \r\6\ca\.es IP address allocation via MAS signalling, the 
container identifier contents field is empty and the length of container identifier 
contents indicates a length equal to zero. If the container identifier contents field is 
not empty, it shall be ignored. 

When the container identifier \r\6\ca\es IP address allocation via DHGPv4, the 
container identifier contents field is empty and the length of container identifier 
contents indicates a length equal to zero. If the container identifier contents field is 
not empty, it shall be ignored. 

When the container identifier indicates MSISDN, the container identifier contents 
field contains the MSISDN (see 3GPP TS 23.003 [10]) assigned to the MS. Use of 
the MSISDN provided is defined in subclause 6.4. 

When the container identifier \n6\cales IFOM Support Request (see 
3GPP TS 24.303 [124] and 3GPP TS 24.327 [125]), the container identifier contents 
field is empty and the length of container identifier contents indicates a length equal 
to zero. If the container identifier contents field is not empty, it shall be ignored. 

When the container identifier \n6\caies IFOM Support, the container identifier 
contents f\e\6 is empty and the length of container identifier contents indicates a 
length equal to zero. If the container identifier contents f\e\6 is not empty, it shall be 
ignored. This information indicates that the Home Agent supports IFOM. 

When the container identifier \n6\caies IPv4 Link MTU Request, the container 
identifier contents field is empty and the length of container identifier contents 
indicates a length equal to zero. If the container identifier contents f\e\6 is not empty, 
it shall be ignored. 

When the container identifier \n6\caies IPv4 Link MTU, the length of container 
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identifier contents indicates a length equal to two. The container identifier contents 
field contains the binary coded representation of the IPv4 link MTU size in octets. Bit 
8 of the first octet of the container identifier contents field contains the most 
significant bit and bit 1 of the second octet of the container identifier contents f\e\6 
contains the least significant bit. If the iengtii of container identifier contents is 
different from two octets, then it shall be ignored by the receiver. 

When the container identifier indicates operator specific use, the Container contents 
starts with MCC and MNC of the operator providing the relevant application and can 
be followed by further application specific information. The coding of MCC and MNC 
is as in octet 2 to 4 of the Location Area Identification information element in 
subclause 10.5.1.3. 

NOTE 1 : The additional parameters //sf and the configuration protocoi options iist 
are logically separated since they carry different type of information. The beginning 
of the additional parameters list\s marked by a logical unit, which has an identifier 
(i.e. the first two octets) equal to a container identifier (\.e. it is not a protocol 
identifier). 



1 0.5.6.4 Packet data protocol address 

The purpose of the paclcet data protocol address information element is to identify an address associated with a PDP. 

The paclcet data protocol address is a type 4 information element with minimum length of 4 octets and a maximum 
length of 24 octets. 

The paclcet data protocol address information element is coded as shown in figure 10.5.137/3GPP TS 24.008 and 
table 10.5.155/3GPP TS 24.008. 



8 


7 6 5 


4 3 2 1 


Packet data protocol address IE! 


Length of PDP address contents 



spare 


PDP type organisation 


PDP type number 


Address information 



octet 1 
octet 2 
octet 3 

octet 4 
octet 5 

octet n 



Figure 1 0.5.1 37/3GPP TS 24.008: Packet data protocol address information element 
Table 1 0.5.1 55/3GPP TS 24.008: Packet data protocol address information element 



Length of PDP address contents (octet 2) 

If the value of octet 2 equals 0000 0010, then: 

No PDP address is included in this information element; and 

- If the PDP type is IP, dynamic addressing is applicable. 

NOTE: For PPP no address Is required in this information element. 

PDP type organisation (octet 3) 

Bits 

4321 

In MS to network direction : 

ETSI allocated address 

1 IETF allocated address 

1111 Empty PDP type 
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All other values are reserved. 

In network to MS direction : 

ETSI allocated address 

1 IETF allocated address 

All other values are reserved. 

If bits 4,3,2,1 of octet 3 are coded 

PDP type number value (octet 4) 

Bits 

8765432 1 

00000000 Reserved, used in earlier version of this protocol 

1 PDP-type PPP 

All other values are reserved 

in this version of the protocol. 

If bits 4,3,2,1 of octet 3 are coded 1 

PDP type number value (octet 4) 

Bits 

8765432 1 

00 1 0000 1 IPv4 address 

10 10 111 IPv6 address 

10 110 1 IPv4v6 address 

All other values shall be interpreted as IPv4 address 
in this version of the protocol. 

In MS to network direction: 

If bits 4,3,2,1 of octet 3 are coded 1111 

PDP type number value (octet 4) 

bits 8 to 1 are spare and shall be coded all 0. 

Octet 3, bits 8, 7, 6, and 5 are spare and shall be coded all 0. 



If PDP type number indicates IPv4, the Address information in octet 5 to octet 8 contains the IPv4 address. Bit 8 of 
octet 5 represents the most significant bit of the IP address and bit 1 of octet 8 the least significant bit. 

If PDP type number indicates IPv6, the Address information in octet 5 to octet 20 contains the IPv6 address. Bit 8 of 
octet 5 represents the most significant bit of the IP address and bit 1 of octet 20 the least significant bit. 

If PDP type number indicates IPv4v6: 

The Address information in octet 5 to octet 8 contains the IPv4 address. Bit 8 of octet 5 represents the most significant 

bit of the IP address and bit 1 of octet 8 the least significant bit. 

The Address information in octet 9 to octet 24 contains the IPv6 address. Bit 8 of octet 9 represents the most significant 

bit of the IP address and bit 1 of octet 24 the least significant bit. 

If PDP type number indicates IPv4 or IPv4v6 and DHCPv4 is to be used to allocate the IPv4 address, the IPv4 address 
shall be coded as 0.0.0.0. 

1 0.5.6.5 Quality of service 

The purpose of the quality of service information element is to specify the QoS parameters for a PDP context. 

The QoS IE is defined to allow backward compatibility to earlier version of Session Management Protocol. 

The quality of service is a type 4 information element with a minimum length of 14 octets and a maximum length of 18 
octets. The QoS requested by the MS shall be encoded both in the QoS attributes specified in octets 3-5 and in the QoS 
attributes specified in octets 6-14. 

In the MS to network direction and in the network to MS direction the following applies: 

Octets 15-18 are optional. If octet 15 is included, then octet 16 shall also be included, and octets 17 and 18 may 
be included. 

If octet 17 is included, then octet 18 shall also be included. 
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A QoS IE received without octets 6-18, without octets 14-18, without octets 15-18, or without octets 17-18 shall 
be accepted by the receiving entity. 

NOTE: This behavior is required for interworking with entities supporting an earlier version of the protocol, or 
when the Maximum bit rate for downlink or for downlink and uplink is negotiated to a value lower than 
8700 kbps. 

The quality of service information element is coded as shown in figure 10.5.138/3GPP TS 24.008 and 
table 10.5.156/3GPP TS 24.008. 



Quality of service lEI 


octet 1 


Length of quality of service IE 


Octet 2 



spare 


Delay 
class 


Reliability 
class 


octet 3 


Peak 
throughput 



spare 


Precedence 
class 


octet 4 



spare 


Mean 
throughput 


octet 5 


Traffic Class 


Delivery order 


Delivery of erroneous 
SDU 


Octet 6 


IVIaximum SDU size 


Octet 7 


Maximum bit rate for uplink 


Octet 8 


IVIaximum bit rate for downlink 


Octet 9 


Residual BER SDU error ratio 


Octet 1 


Transfer delay 


Traffic Handling 
priority 


Octet 1 1 


Guaranteed bit rate for uplink 


Octet 1 2 


Guaranteed bit rate for downlink 


Octet 1 3 



spare 


Signal- 
ling 

Indicat- 
ion 


Source Statistics Descriptor 


Octet 14 


Maximum bit rate for downlink (extended) 


Octet 1 5 


Guaranteed bit rate for downlink (extended) 


Octet 1 6 


Maximum bit rate for uplink (extended) 


Octet 1 7 


Guaranteed bit rate for uplink (extended) 


Octet 1 8 



Figure 1 0.5.1 38/3GPP TS 24.008: Quality of service information element 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 544 ETSI TS 124 008 VI 0.1 0.0 (2013-04) 

Table 1 0.5.1 56/3GPP TS 24.008: Quality of service information element 

Reliability class, octet 3 (see 3GPP TS 23.107 [81]) 

Bits 

321 

In MS to network direction: 

Subscribed reliability class 

In network to MS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 Unused. If received, it shall be interpreted as '010' (Note) 

1 Unacknowledged GTP; Acknowledged LLC and RLC, Protected data 

1 1 Unacknowledged GTP and LLC; Acknowledged RLC, Protected data 

1 Unacknowledged GTP, LLC, and RLC, Protected data 

1 1 Unacknowledged GTP, LLC, and RLC, Unprotected data 
1 1 1 Reserved 

All other values are interpreted as Unacknowledged GTP and LLC; Acknowledged RLC, Protected data in this version of 
the protocol. 

If network supports EPS, then it should not assign Reliability class value '01 0'. 

NOTE: this value was allocated in earlier versions of the protocol. 

Delay class, octet 3 (see 3GPP TS 22.060 [73] and 3GPP TS 23.107 [81]) 

Bits 

654 

In MS to network direction: 

Subscribed delay class 

In network to MS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 Delay class 1 

1 Delay class 2 

1 1 Delay class 3 

1 Delay class 4 (best effort) 
1 1 1 Reserved 
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All other values are interpreted as Delay class 4 (best effort) in this version 

of the protocol. 

Bit 7 and 8 of octet 3 are spare and shall be coded all 0. 

Precedence class, octet 4 (see 3GPP TS 23.107 [81]) 

Bits 

321 

In MS to network direction: 

Subscribed precedence 

In network to IVIS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 High priority 

1 Normal priority 

1 1 Low priority 

1 1 1 Reserved 

All other values are interpreted as Normal priority in this version of the protocol. 

Bit 4 of octet 4 is spare and shall be coded as 0. 

Peak throughput, octet 4 (see 3GPP TS 23.107 [81]) 

This field is the binary representation of the Peak Throughput Class (1 to 9). The corresponding peak throughput to each 

peak throughput class is indicated. 

Bits 

8765 

In MS to network direction: 

Subscribed peak throughput 

In network to MS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 Up to 1 000 octet/s 

10 Up to 2 000 octet/s 

11 Up to 4 000 octet/s 

10 Up to 8 000 octet/s 

10 1 Up to 16 000 octet/s 

110 Up to 32 000 octet/s 

111 Up to 64 000 octet/s 

10 00 Up to 128 000 octet/s 

10 1 Up to 256 000 octet/s 

1111 Reserved 

All other values are interpreted as Up to 1 000 octet/s in this 

version of the protocol. 

Mean throughput, octet 5 (see 3GPP TS 23.107 [81]) 

This field is the binary representation of the Mean Throughput Class (1 to 18; mean throughput class 30 is reserved and 

31 is best effort). The corresponding mean throughput to each mean throughput class is indicated. 

Bits 

54321 
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In MS to network direction: 

Subscribed mean throughput 

In network to IVIS direction: 

Reserved 

In IVIS to network direction and in network to IVIS direction: 

1 1 00 octet/h 

10 200 octet/h 

11 500 octet/h 

10 1 000 octet/h 

10 1 2 000 octet/h 

110 5 000 octet/h 

111 1 000 octet/h 

10 20 000 octet/h 

10 1 50 000 octet/h 

10 10 1 00 000 octet/h 

10 11 200 000 octet/h 

110 500 000 octet/h 

110 1 1 000 000 octet/h 

1110 2 000 000 octet/h 

1111 5 000 000 octet/h 

10 1 000 000 octet/h 

10 1 20 000 000 octet/h 

10 10 50 000 000 octet/h 

11110 Reserved 

11111 Best effort 

The value Best effort indicates that throughput shall be made available to the IVIS on a per need and availability basis. 
All other values are interpreted as Best effort in this 
version of the protocol. 

Bits 8 to 6 of octet 5 are spare and shall be coded all 0. 

Delivery of erroneous SDUs, octet 6 (see 3GPP TS 23.107 [81]) 

Bits 

32 1 

In IVIS to network direction: 

Subscribed delivery of erroneous SDUs 

In network to IVIS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 No detect {'-') 

1 Erroneous SDUs are delivered {'yes') 

1 1 Erroneous SDUs are not delivered {'no') 

1 1 1 Reserved 

The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of this protocol. 

The MS shall consider all other values as reserved. 

Delivery order, octet 6 {see 3GPP TS 23.107 [81]) 

Bits 

543 

In MS to network direction: 

Subscribed delivery order 

In network to MS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 With delivery order ('yes') 

1 Without delivery order ('no') 
1 1 Reserved 
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Traffic class, octet 6 (see 3GPP TS 23.107 [81]) 

Bits 

876 

In MS to network direction: 

Subscribed traffic class 

In network to MS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 Conversational class 

1 Streaming class 

1 1 Interactive class 

1 Background class 
1 1 1 Reserved 

The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of this protocol. 

The MS shall consider all other values as reserved. 

Maximum SDU size, octet 7 (see 3GPP TS 23.107 [81]) 

In MS to network direction: 

00000000 Subscribed maximum SDU size 

11111111 Reserved 

In network to MS direction: 

00000000 Reserved 

11111111 Reserved 

In MS to network direction and in network to MS direction: 

For values in the range 00000001 to 1 001 01 1 the Maximum SDU size value is binary coded in 8 bits, using a 

granularity of 1 octets, giving a range of values from 1 octets to 1 500 octets. 

Values above 1 001 01 1 are as below: 

10010111 1502 octets 

100 11000 1510 octets 

10011001 1520 octets 

The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of this protocol. 

The MS shall consider all other values as reserved. 

Maximum bit rate for uplink, octet 8 

Bits 

87654321 

In MS to network direction: 

00000000 Subscribed maximum bit rate for uplink 

In network to MS direction: 

00000000 Reserved 

In MS to network direction and in network to MS direction: 

1 The maximum bit rate is binary coded in 8 bits, using a granularity of 1 kbps 

111111 giving a range of values from 1 kbps to 63 kbps in 1 kbps increments. 

1 The maximum bit rate is 64 kbps + ((the binary coded value in 8 bits -01 000000) * 8 kbps) 
1111111 giving a range of values from 64 kbps to 568 kbps in 8 kbps increments. 

10 The maximum bit rate is 576 kbps + ((the binary coded value in 8 bits -1 0000000) * 64 kbps) 

11111110 giving a range of values from 576 kbps to 8640 kbps in 64 kbps increments. 

11111111 0kbps 

If the sending entity wants to indicate a Maximum bit rate for uplink higher than 8640 kbps, it shall set octet 8 to 
"1111111 0", i.e. 8640 kbps, and shall encode the value for the Maximum bit rate in octet 1 7. 
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Maximum bit rate for downlinl<, octet 9 (see 3GPP TS 23.107 [81]) 

Coding is identical to that of IVIaximum bit rate for uplinl<. 

If the sending entity wants to indicate a Maximum bit rate for downlink higher than 8640 kbps, it shall set octet 9 to 
"11111110", i.e. 8640 kbps, and shall encode the value for the Maximum bit rate in octet 15. 

In this version of the protocol, for messages specified in the present document, the sending entity shall not request 
kbps for both the Maximum bitrate for downlink and the Maximum bitrate for uplink at the same time. Any entity receiving 
a request for kbps in both the Maximum bitrate for downlink and the Maximum bitrate for uplink shall consider that as a 
syntactical error (see clause 8). 



Residual Bit Error Rate (BER), octet 10 (see 3GPP TS 23.107 [81]) 






Bits 






8765 






In MS to network direction: 






Subscribed residual BER 






In network to MS direction: 






Reserved 






In MS to network direction and in network to MS direction: 






The Residual BER value consists of 4 bits. The range is from 5*10"^ to 6*10''*. 




000 1 5*10"^ 






00 10 1*10"^ 






00 11 5*10"^ 






100 4*10"^ 






10 1 1*10"^ 






0110 1*10"" 






0111 1*10"^ 






10 00 1*10"^ 






100 1 6*10"® 






1111 Reserved 






The network shall map all other values not explicitly defined onto one 


of the values defined in this version of the protocol. 


The network shall return a negotiated value which is explicitly defined 


in this version 


of the protocol. 


The MS shall consider all other values as reserved. 






SDU error ratio, octet 10 (see 3GPP TS 23.107 [81]) 






Bits 






4321 






In MS to network direction: 






Subscribed SDU error ratio 






In network to MS direction: 






Reserved 






In MS to network direction and in network to MS direction: 






The SDU error ratio value consists of 4 bits. The range is is from 1*10 


"'to1*10"^ 




000 1 1*10"^ 






00 10 7*10"® 






00 11 1*10"® 






100 1*10"" 






10 1 1*10"^ 






0110 1*10"^ 






111 1*10"^ 






1111 Reserved 






The network shall map all other values not explicitly defined onto one 


of the values defined in this version of the protocol. 


The network shall return a negotiated value which is explicitly defined 


in this version 


of the protocol. 


The MS shall consider all other values as reserved. 






Traffic handling priority, octet 11 (see 3GPP TS 23.107 [81]) 






Bits 






21 






In MS to network direction: 






Subscribed traffic handling priority 
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In network to MS direction: 

Reserved 

In IVIS to networl< direction and in networl< to IVIS direction: 

1 Priority level 1 

1 Priority level 2 
1 1 Priority level 3 

The Traffic handling priority value is ignored if the Traffic Class is Conversational class, Streaming class or Background 
class. 

Transfer delay, octet 1 1 (See 3GPP TS 23.107 [81]) 

Bits 

876543 



In IVIS to network direction: 

Subscribed transfer delay 

In network to MS direction: 

Reserved 

In MS to network direction and in network to MS direction: 

1 The Transfer delay is binary coded in 6 bits, using a granularity of 1 ms 
1111 giving a range of values from 1 ms to 1 50 ms in 1 ms increments 

10 The transfer delay is 200 ms + ((the binary coded value in 6 bits - 01 0000) * 50 ms) 
11111 giving a range of values from 200 ms to 950 ms in 50ms increments 

10 The transfer delay is 1 000 ms + ((the binary coded value in 6 bits - 1 00000) * 1 00 ms) 

111110 giving a range of values from 1 000 ms to 4000 ms in 1 00ms increments 

111111 Reserved 

The Transfer delay value is ignored if the Traffic Class is Interactive class or Background class. 

Guaranteed bit rate for uplink, octet 12 (See 3GPP TS 23.107 [81]) 

Coding is identical to that of Maximum bit rate for uplink. 

If the sending entity wants to indicate a Guaranteed bit rate for uplink higher than 8640 kbps, it shall set octet 12 to 
"1111111 0", i.e. 8640 kbps, and shall encode the value for the Guaranteed bit rate in octet 1 8. 

The Guaranteed bit rate for uplink value is ignored if the Traffic Class is Interactive class or Background class, or 
Maximum bit rate for uplink is set to kbps. 

Guaranteed bit rate for downlink, octet 13(See 3GPP TS 23.107 [81]) 

Coding is identical to that of Maximum bit rate for uplink. 

If the sending entity wants to indicate a Guaranteed bit rate for downlink higher than 8640 kbps, it shall set octet 13 to 
"11111 110", i.e. 8640 kbps, and shall encode the value for the Guaranteed bit rate in octet 16. 

The Guaranteed bit rate for downlink value is ignored if the Traffic Class is Interactive class or Background class, or 
Maximum bit rate for downlink is set to kbps. 

Source Statistics Descriptor, octet 14 (see 3GPP TS 23.107 [81]) 

Bits 

4321 

In MS to network direction 

unknown 

1 speech 

The network shall consider all other values as unknown. 

In network to MS direction 

Bits 4 to 1 of octet 14 are spare and shall be coded all 0. 
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The Source Statistics Descriptor value is ignored if the Traffic Class is Interactive class or Background class. 

Signalling Indication, octet 14 (see 3GPP TS 23.107 [81]) 

Bit 

5 

In MS to network direction and in network to MS direction: 

Not optimised for signalling traffic 

1 Optimised for signalling traffic 

If set to '1 ' the QoS of the PDP context is optimised for signalling 

The Signalling Indication value is ignored if the Traffic Class is Conversational class, Streaming class or Background 
class. 

Bits 8 to 6 of octet 14 are spare and shall be coded all 0. 



Maximum bit rate for downlink (extended), octet 1 5 

Bits 

87654321 

In MS to network direction and in network to MS direction: 

00000000 Use the value indicated by the Maximum bit rate for downlink in octet 9. 

For all other values: Ignore the value indicated by the Maximum bit rate for downlink in octet 9 

and use the following value: 
1 The maximum bit rate is 8600 kbps + ((the binary coded value In 8 bits) * 100 kbps), 
10 10 10 giving a range of values from 8700 kbps 
to 16000 kbps in 100 kbps increments. 

10 10 11 The maximum bit rate is 1 6 Mbps + ((the binary coded value in 8 bits - 01 001 01 0) * 1 Mbps), 
10 1110 10 giving a range of values from 17 Mbps to 128 Mbps in 1 Mbps increments. 

10 1110 11 The maximum bit rate is 1 28 Mbps + ((the binary coded value in 8 bits - 1 01 1 1 01 0) * 2 Mbps), 
111110 10 giving a range of values from 130 Mbps to 256 Mbps in 2 Mbps increments. 

The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of the protocol. 

The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol. 

Guaranteed bit rate for downlink (extended), octet 16 

Bits 

87654321 

In MS to network direction and in network to MS direction: 

00000000 Use the value indicated by the Guaranteed bit rate for downlink in octet 1 3. 

For all other values: Ignore the value indicated by the Guaranteed bit rate for downlink in octet 9 

and use the following value: 
1 The guaranteed bit rate is 8600 kbps + ((the binary coded value in 8 bits) * 1 00 kbps), 
10 10 10 giving a range of values from 8700 kbps to 1 6000 kbps in 1 00 kbps increments. 

10 10 11 The guaranteed bit rate is 16 Mbps + ((the binary coded value in 8 bits - 01001010) * 1 Mbps), 
10 1110 10 giving a range of values from 17 Mbps to 128 Mbps in 1 Mbps increments. 

10 1110 11 The guaranteed bit rate is 1 28 Mbps + ((the binary coded value in 8 bits - 1 01 1 1 01 0) * 2 Mbps), 
111110 10 giving a range of values from 130 Mbps to 256 Mbps in 2 Mbps increments. 

The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of the protocol. 

The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol. 

Maximum bit rate for uplink (extended), octet 17 

This field is an extension of the Maximum bit rate for uplink in octet 8. The coding is identical to that of the Maximum bit 
rate for downlink (extended). 
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The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of the protocol. 

The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol. 

Guaranteed bit rate for uplink (extended), octet 18 

This field is an extension of the Guaranteed bit rate for uplink in octet 12. The coding is identical to that of the 
Guaranteed bit rate for downlink (extended). 

The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol. 
The network shall return a negotiated value which is explicitly defined in this version of the protocol. 

The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol. 



10.5.6.6 SM cause 

The purpose of the SM cause information element is to indicate the reason why a session management request is 
rejected. 

The SM cause is a type 3 information element with 2 octets length. 

The SM cause information element is coded as shown in figure 10.5. 139/3GPP TS 24.008 and table 10.5. 157/3GPP TS 
24.008. 



SM cause lEI 



Cause value 



octet 1 
octet 2 



Figure 1 0.5.1 39/3GPP TS 24.008: SM cause information element 
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Table 1 0.5.1 57/3GPP TS 24.008: SM cause information element 



Cause value (octet 2) 

Bits 

8765432 

0000100 



1 00 

1 00 

1 1 

1 1 

1 1 

1 1 

1 1 1 

1 1 1 



0001 
0001 
0001 
0001 
0001 
0001 
0001 
0001 
00 10000 
00 10000 
00 10001 
0010001 
00 10010 
00 10010 
00 10011 
00 1001 1 
00 10100 
00 10100 
00 10101 
00 10101 
0010110 
0010110 
0010111 
0010111 
00 11000 
00 11001 
00 11001 
1010 
1100 
1110 
0101000 
0101111 
10000 
10000 
1000 1 
10001 
10010 
10010 
10111 
11000 



00 1 
00 1 
00 1 



01 
01 
01 
01 
01 
01 
01 
01 



1 

Operator Determined Barring 

IVIBIVIS bearer capabilities insufficient for the service 

1 LLC or SNDCPfailure(A/Gb mode only) 

Insufficient resources 

1 IVIissing or unknown APN 

Unknown PDP address or PDP type 

1 User authentication failed 

Activation rejected by GGSN, Serving GW or PDN GW 

1 Activation rejected, unspecified 

Service option not supported 

1 Requested service option not subscribed 

Service option temporarily out of order 

1 NSAPI already used (not sent) 

Regular deactivation 

1 QoS not accepted 

Network failure 

1 Reactivation requested 

Feature not supported 

1 Semantic error in the TFT operation 

Syntactical error in the TFT operation 

1 Unknown PDP context 

Semantic errors in packet filter(s) 

1 Syntactical errors in packet filter(s) 

PDP context without TFT already activated 

1 IVIulticast group membership time-out 
Request rejected, BCM violation 

PDP type IPv4 only allowed 

1 PDP type IPv6 only allowed 

Single address bearers only allowed 

Collision with network initiated request 

Bearer handling not supported 

1 Invalid transaction identifier value 
1 Semantically incorrect message 

Invalid mandatory information 

1 IVIessage type non-existent or not implemented 

Message type not compatible with the protocol state 

1 Information element non-existent or not implemented 

Conditional IE error 

1 Message not compatible with the protocol state 
1 Protocol error, unspecified 

APN restriction value incompatible with active PDP context 



Any other value received by the mobile station shall be treated as 001 001 0, "Service 
option temporarily out of order". Any other value received by the network shall be treated as 
0110 1111, "Protocol error, unspecified". 

NOTE: The listed cause values are defined in Annex I 



10.5.6.6A SM cause 2 

The purpose of the SM cause 2 information element is to provide further information when PDP context activation 
initiated by the mobile station is successful. 

The SM cause 2 is a type 4 information element with 3 octets length. 

The SM cause 2 information element is coded as shown in figure 10.5.139a/3GPP TS 24.008 and table 10.5.157a/3GPP 
TS 24.008. 
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6 5 4 3 


2 


1 


SM cause 2 lEI 


Length of SM cause 2 contents 


SM cause 2 value 
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octet 1 
octet 2 
octet 3 



Figure 1 0.5.1 39a/3GPP TS 24.008: SM cause 2 information element 
Table 1 0.5.1 57a/3GPP TS 24.008: SM cause 2 information element 



SM cause 2 value is coded as octet 2 of the SM cause information element. 



10.5.6.7 



Linked Tl 



The purpose of the Linked TI information element is to specify the active PDP context from which the PDP address for 
the new PDP context could be derived by the network. 

The Linked TI is a type 4 information element with a minimum length of 3 octets and a maximum length of 4 octets. 

The Linked TI information element is coded as shown in figure 10.5. 140/3GPP TS 24.008. 



Linked TI IE! 


Length of Linked TI IE 


TI flag 


TI value 


0000 
Spare 


1 
EXT 


TI value 



octet 1 
octet 2 

octet 3 
octet 4 

Figure 10.5.140/3GPP TS 24.008: Linked 7/ information element 

The coding of the TI flag, the TI value and the EXT bit is defined in 3GPP TS 24.007[20]. 

10.5.6.8 Spare 

1 0.5.6.9 LLC service access point identifier 

The purpose of the LLC service access point identifier information element is to identify the service access point that is 
used for the GPRS data transfer at LLC layer. 

The LLC service access point identifier is a type 3 information element with a length of 2 octets. 

The value part of a LLC service access point identifier information element is coded as shown in figure 10.5.141/3GPP 
TS 24.008 and table 10.5.159/3GPP TS 24.008. 



8 


7 6 


5 


4 


3 2 


1 


LLC SAPI lEI 1 



Spare 


LLC SAPI 
value 



octet 1 
octet 2 



Figure 10.5.141/3GPP TS 24.008: LLC service access point identifier iniormation element 
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Table 1 0.5.1 59/3GPP TS 24.008: LLC service access point identifier information element 



LLC SAPI value (octet 2) 


Bit 




4321 




0000 


LLC SAPI not assigned 


0011 


SAPI 3 


01 01 


SAPI 5 


1001 


SAPI 9 


1011 


SAPI 11 


All other 


values are reserved. 



10.5.6.10 Tear down indicator 

The purpose of the tear down indicator information element is to indicate whether only the PDP context associated with 
this specific TI or all active PDP contexts sharing the same PDP address and APN as the PDP context associated with 
this specific TI shall be deactivated. 

The tear down indicator is a type 1 information element. 

The tear down indicator information element is coded as shown in figure 10.5.142/3GPP TS 24.008 and 
table 10.5.160/3GPP TS 24.008. 



Tear down indicator 
lEI 



spare 


TDI 

flag 



octet 1 

Figure 1 0.5.1 42/3GPP TS 24.008: Tear down ;nc/;cafof information element 
Table 10.5.160/3GPP TS 24.008: Tear down ;nc/;catof information element 



Tear down indicator(TDI) flag (octet 1) 



Bit 
1 



1 



tear down not requested 
tear down requested 



1 0.5.6.1 1 Packet Flow Identifier 

The Packet Flow Identifier (PFI) information element indicates the Packet Flow Identifier for a Packet Flow Context. 

The Packet Flow Identifier is a a type 4 information element with 3 octets length. 

The Packet Flow Identifier information element is coded as shown in figure 10.5.143/3GPP TS 24.008 and 
table 10.5.161/3GPP TS 24.008. 
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Packet Flow Identifier lEI 



Spare 




Length of Packet Flow Identifier IE 



Packet Flow Identifier value 



octet 1 
octet 2 
octet 3 



Figure 10.5.143/3GPP TS 24.008: Packet Flow Identifier information element 
Table 10.5.161/3GPP TS 24.008: Packet Flow Identifier information element 



Packet Flow Identifier value (octet 3) 

Bits 

7654321 

Best Effort 

1 Signaling 

00000 10 SMS 

1 1 TOMS 

0000100 } 

to } reserved 

0000111 } 

0001000 } 

to } dynamically assigned 

1111111 } 



1 0.5.6.1 2 Traffic Flow Template 

The purpose of the traffic flow template information element is to specify the TFT parameters and operations for a PDP 
context. In addition, this information element may be used to transfer extra parameters to the network (e.g. the 
Authorization Token; see 3GPP TS 24.229 [95]). The TFT may contain packet filters for the downlink direction, the 
uplink direction or packet filters that apply for both directions. The packet filters determine the traffic mapping to PDP 
contexts. The downlink packet filters shall be applied by the network and the uplink packet filters shall be applied by 
the MS. A packet filter that applies for both directions shall be applied by the network as a downlink packet filter and 
by the MS as an uplink filter. 

The traffic flow template is a type 4 information element with a minimum length of 3 octets. The maximum length for 
the IE is 257 octets. 

NOTE 1 : The IE length restriction is due to the maximum length that can be encoded in a single length octet. 

NOTE 2: A maximum size IPv4 packet filter can be 32 bytes. Therefore, 7 maximum size IPv4 type packet filters, 
plus the last packet filter which can contain max 30 octets can fit into one TFT IE, i.e. if needed not all 
packet filter components can be defined into one message. A maximum size IPv6 packet filter can be 60 
bytes. Therefore, only 4 maximum size IPv6 packet filters can fit into one TFT IE. However, using "Add 
packet filters to existing TFT", it's possible to create a TFT data structure including 16 maximum size 
IPv4 or IPv6 filters. 

The traffic flow template information element is coded as shown in figure 10.5.144/3GPP TS 24.008 and table 
10.5.162/3GPPTS 24.008. 
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8 7 6 5 4 3 2 1 



Traffic flow template lEI 



Length of traffic flow template IE 



TFT operation code E bit Number of packet filters 



Packet filter list 



Parameters list 



Octet 1 
Octet 2 
Octet 3 
Octet 4 

Octet z 
Octet z+1 

Octet V 



Figure 10.5.144/3GPP TS 24.008: Traffic flow template information element 



8 7 6 5 


4 3 2 1 


Packet filter 


identifier 1 


Packet filter 


identifier 2 




Packet filter identifier N 



Octet 4 
Octet 5 



Octet N+3 

Figure 1 0.5.1 44a/3GPP TS 24.008: Packet filter /;sf when the TFT operation is "delete packet filters 

from existing TFT" (z=N+3) 



8 


7 6 5 4 3 2 


1 


Packet filter identifier 1 


Packet filter evaluation precedence 1 


Length of Packet filter contents 1 


Packet filter contents 1 


Packet filter identifier 2 


Packet filter evaluation precedence 2 


Length of Packet filter contents 2 


Packet filter contents 2 




Packet filter identifier N 


Packet filter evaluation precedence N 


Length of Packet filter contents N 


Packet filter contents N 



Octet 4 
Octet 5 
Octet 6 
Octet 7 
Octet m 
Octet m+1 
Octet m+2 
Octet m+3 
Octet m+4 
Octet n 
Octet n+1 
Octet y 
Octet y+1 
Octet y+2 
Octet y+3 
Octet y+4 
Octet z 

Figure 1 0.5.1 44b/3GPP TS 24.008: Packet filter list \Nhen the TFT operation is "create new TFT", or 
"add packet filters to existing TFT" or "replace packet filters in existing TFT" 
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8 


7 6 5 4 3 2 


1 


Parameter identifier 1 


Length of Parameter contents 1 


Parameter contents 1 


Parameter identifier 2 


Length of Parameter contents 2 


Parameter contents 2 




Parameter identifier N 


Length of Parameter contents N 


Parameter contents N 



Octet z+1 
Octet z+2 
Octet z+3 
Octet k 
Octet k+1 
Octet k+2 
Octet k+3 
Octet p 
Octet p+1 
Octet q 
Octet q+1 
Octet q+2 
Octet q+3 
Octet V 



Figure 1 0.5.1 44c/3GPP TS 24.008: Parameters list 
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Table 1 0.5.1 62/3GPP TS 24.008: Traffic flow template information element 



TFT operation code (octet 3) 

Bits 

876 

Spare 

1 Create new TFT 

1 Delete existing TFT 

1 1 Add pacl<et filters to existing TFT 

1 Replace packet filters in existing TFT 

1 1 Delete packet filters from existing TFT 
1 1 No TFT operation 
1 1 1 Reserved 

The TFT operation code "No TFT operation" shall be used if a parameters list is 
included but no packet filter list is included in the traffic flow template information 
element. 

E bit (bit 5 of octet 3) 

The £ bit indicates if a parameters list is included in the TFT IE and it is encoded as 

follows: 

parameters list\s not included 

1 parameters //sf is included 

Number of packet filters (octet 3) 

The number of packet filters contains the binary coding for the number of packet 
filters in the packet filter list. The number of packet filters field is encoded in bits 4 
through 1 of octet 3 where bit 4 is the most significant and bit 1 is the least 
significant bit. For the "delete existing TFT" operation and for the "no TFT 
operation", the number of packet filters shall be coded as 0. For all other operations, 
the number of packet filters shall be greater than and less than or equal to 1 5. 

Packet filter list (octets 4 to z) 

The packet filter list conXams a variable number of packet filters. For the "delete 

existing TFT" operation and the "no TFT operation", the packet filter list shaW be 

empty. 

For the "delete packet filters from existing TFT" operation, the packet filter list shaW 

contain a variable number of packet filter identifiers. This number shall be derived 

from the coding of the number of packet filters field in octet 3. 

For the "create new TFT", "add packet filters to existing TFT" and "replace packet 
filters in existing TFT" operations, the packet filter list sUaW contain a variable 
number of packet filters. This number shall be derived from the coding of the 
number of packet filters field in octet 3. 

Each packet filter is of variable length and consists of 

- a packet filter identifier and direction (1 octet); 

- a packet filter evaluation precedence (1 octet); 

- the length of the packet filter contents (1 octet); and 

- the packet filter contents itself (v octets). 

The packet filter identifier i\e\6 is used to identify each packet filter in a TFT. The 
least significant 4 bits are used. 

The packet filter direction is used to indicate, in bits 5 and 6, for what traffic direction 
the filter applies: 

00 - pre Rel-7 TFT filter 

01 - downlink only 

10 - uplink only 

1 1 - bidirectional 

Bits 8 through 7 are spare bits. 

The packet filter evaluation precedence field is used to specify the precedence for 
the packet filter among all packet filters in all TFTs associated with this PDF 
address. Higher the value of the packet filter evaluation precedence field, lower the 
precedence of that packet filter is. The first bit in transmission order is the most 
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significant bit. 

Tlie length of the packet filter contents field contains tlie binary coded 
representation of tine lengtli of tlie packet filter contents field of a packet filter. The 
first bit in transmission order is the most significant bit. 

The packet filter contents field is of variable size and contains a variable number (at 
least one) of packet filter components. Each packet filter component shaW be 
encoded as a sequence of a one octet packet filter component type identifier and a 
fixed length packet filter component value field. The packet filter component type 
identifier shaW be transmitted first. 

In each packet filter, there shall not be more than one occurrence of each packet 
filter component type. Among the "IPv4 remote address type" and "IPv6 remote 
address type" packet filter components, only one shall be present in one packet 
filter. Among the "single local port type" and "local port range type" packet filter 
components, only one shall be present in one packet filter. Among the "single 
remote port type" and "remote port range type" packet filter components, only one 
shall be present in one packet filter. 

The term local refers to the MS and the term remote refers to an external network 
entity. 

Packet filter component type identifier 

Bits 

8765432 1 

00010000 

00100000 

00110000 

01000000 

0100000 1 

01010000 

1010001 

01100000 

01110000 

10000000 

All other values 



IPv4 remote address type 
IPv6 remote address type 
Protocol identifier/Next header type 
Single local port type 
Local port range type 
Single remote port type 
Remote port range type 
Security parameter index type 
Type of service/Traffic class type 
Flow label type 
are reserved. 



For "IPv4 remote address type", the packet filter component value field shall be 
encoded as a sequence of a four octet IPv4 address field and a four octet IPv4 
address mask field. The IPv4 address field shall be transmitted first. 

For "IPv6 remote address type", the packet filter component value field shall be 
encoded as a sequence of a sixteen octet IPv6 address field and a sixteen octet 
IPv6 address maskf\e\6. The IPv6 address field shall be transmitted first. 

For "Protocol identifier/Next header type", the packet filter component value field 
shall be encoded as one octet which specifies the IPv4 protocol identifier or IPv6 
next header. 

For "Single local port type" and "Single remote port type", the packet filter 
component value field shall be encoded as two octet which specifies a port number. 

For "Local port range type" and "Remote port range type", the packet filter 
component value field shall be encoded as a sequence of a two octet port range low 
limit f\e\6 and a two octet port range high //Vn/f field. The port range low //m/f field 
shall be transmitted first. 

For "Security parameter index", the packet filter component value f\e\6 shall be 
encoded as four octet which specifies the IPSec security parameter index. 

For "Type of service/Traffic class type", the packet filter component value field shall 
be encoded as a sequence of a one octet Type-of-Service/Traffic Class field and a 
one octet Type-of-Service/Traffic Class maski\e\6. The Type-of-Service/Traffic 
C/ass field shall be transmitted first. 

For "Flow label type", the packet filter component value field shall be encoded as 
three octet which specifies the IPv6 flow label. The bits 8 through 5 of the first octet 
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shall be spare whereas the remaining 20 bits shall contain the IPv6 flow label. 
Parameters list (octets z+1 to v) 

The parameters //sf contains a variable number of parameters that may be 
transferred. If the parameters //sf is included, the EM is set to 1 ; otherwise, the E bit 
is set to 0. 

Each parameter included in the parameters //sf is of variable length and consists of: 

- a parameter identifier (1 octet); 

- the length of the parameter contents (1 octet); and 

- the parameter contents itself (v octets). 

The parameter identifier i\e\6 is used to identify each parameter included in the 
parameters //sf and it contains the hexadecimal coding of the parameter identifier. 
Bit 8 of the parameter identifier f\e\6 contains the most significant bit and bit 1 
contains the least significant bit. In this version of the protocol, the following 
parameter identifiers are specified: 

- 01 H (Authorization Tol<en); 

- 02H (Flow Identifier); and 

- 03H (Packet Filter Identifier). 

If the parameters //sf contains a parameter identifier that is not supported by the 
receiving entity the corresponding parameter shall be discarded. 
The lengtti of parameter contents i\e\6 contains the binary coded representation of 
the length of the parameter contents f\e\6. The first bit in transmission order is the 
most significant bit. 

When the parameter identifier \nd\cates Authorization Token, the parameter 
contents f\e\6 contains an authorization token, as specified in 3GPP TS 29.207 
[100]. The first octet is the most significant octet of the authorization token and the 
last octet is the least significant octet of the authorization token. 
The parameters //sf shall be coded in a way that an Authorization Token (i.e. a 
parameter with identifier 01 H) is always followed by one or more Flow Identifiers 
(i.e. one or more parameters with identifier 02H). 

If the parameters //sf contains two or more consecutive Authorization Tokens without 
any Flow Identifiers in between, the receiver shall treat this as a semantical TFT 
error. 

When the parameter identifier \n6\cates Flow Identifier, the parameter contents f\e\d 
contains the binary representation of a flow identifier. The Flow Identifier consists of 
four octets. Octets 1 and 2 contains the Me6\a Component number as specified in 
3GPP TS 29.207 [100]. Bit 1 of octet 2 is the least significant bit, and bit 8 of octet 1 
is the most significant bit. Octets 3 and 4 contains the IP flow number as specified in 
3GPP TS 29.207 [100]. Bit 1 of octet 4 is the least significant bit, and bit 8 of octet 3 
is the most significant bit. 

When the parameter identifier indicates Packet Filter Identifier, the parameter 
contents field contains the binary representation of one or more packet filter 
identifiers. Each packet filter identifier is encoded in one octet, in the 4 least 
significant bits. This parameter is used by the MS to identify one or more packet 
filters in a TFT when modifying the QoS of a PDP context without modifying the 
packet filter itself. 



1 0.5.6.1 3 Temporary Mobile Group Identity (TMGI) 

The purpose of the TMGI element is for group paging in MBMS. 

The TMGI information element is a type 4 information element with a minimum length of 5 octets and a maximum 
length of 8 octets. If octet 6 is included, then octets 7 and 8 shall also be included. 

The content of the TMGI element is shown in Figure 10.5.154/3GPP TS 24.008 and table 10.5.168/3GPP TS 24.008. 
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8 7 6 5 


4 3 2 1 


Temporary Mobile Group Identity lEI 


Length of Temporary Mobile Group Identity contents 


MBMS Service ID 


MOO digit 2 


MCC digit 1 


MNCdigitS 


MCCdigit3 


MNGdigit2 


MNC digit 1 



Octet 1 
Octet 2 
Octet 3 
Octet 4 
Octet 5 
Octet 6* 
Octet T 
Octet 8* 



Figure 1 0.5.1 54/3GPP TS 24.008: TMGI information element 
Table 10.5.168/3GPP TS 24.008: 7MG/ information element 



MBMS Service ID (octet 3, 4 and 5) 

In the MBMS Service ID field bit 8 of octet 3 is the most significant bit and bit 1 of octet 5 the least significant bit. 
The coding of the MBMS Service ID is the responsibility of each administration. Coding using full hexadecimal 
representation may be used. The MBMS Service ID consists of 3 octets. 

MCC, Mobile country code (octet 6, octet 7 bits 1 to 4) 

The MCC field is coded as in ITU-T Rec. E.212, Annex A. 

MNC, Mobile network code (octet 7 bits 5 to 8, octet 8) 

The coding of this field is the responsibility of each administration but BCD coding shall be used. The MNC shall 
consist of 2 or 3 digits. If a network operator decides to use only two digits in the MNC, bits 5 to 8 of octet 7 shall 
be coded as "1111". 



1 0.5.6.1 4 MBMS bearer capabilities 

The purpose of the MBMS bearer capabilities information element is to indicate the maximum bit rate for downlink 
supported by the MS for an MBMS context. 

NOTE: The information element indicates the static physical capabilities of the MS, independent of the radio 
access (UTRAN or GERAN), the radio conditions, or other CS or PS services possibly activated by the 
MS. 

The MBMS bearer capabilities is a type 4 information element with a maximum length of 4 octets. 

The MBMS bearer capabilities information element is coded as shown in figure 10.5. 155/3GPP TS 24.008 and 
table 10.5.169/3GPP TS 24.008. 



MBMS bearer capabilities lEI 



Length of MBMS bearer capabilities IE 



Maximum bit rate for downlink 



Maximum bit rate for downlink (extended) 



Octet 1 
Octet 2 
Octet 3 
Octet 4 



Figure 1 0.5.1 55/3GPP TS 24.008: MBMS bearer capabilities information element 
Table 1 0.5.1 69/3GPP TR 24.008: MBMS bearer capabilities information element 
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Maximum bit rate for downlinl<, octet 3 (see 3GPP TS 23.107 [81]) 

The coding is identical to that of the maximum bit rate for downlinl<, octet 9, in the Quality of service information element 
(see subclause 10.5.6.5). 

If the sending entity wants to indicate a maximum bit rate for downlink higher than 8640 kbps, it shall set octet 3 to 
"11111 110", i.e. 8640 kbps, and shall encode the value for the maximum bit rate in octet 4. 

IVIaximum bit rate for downlink (extended), octet 4 

The coding is identical to that of the maximum bit rate for downlink (extended), octet 15, in the Quality of service 
information element (see subclause 10.5.6.5). 



10.5.6.15 MBMS protocol configuration options 

The purpose of the MBMS protocol configuration options information element is to: 

transfer protocol options associated with the bearer level of an MBMS context activation, and 

transfer additional MBMS bearer related (protocol) data (e.g. configuration parameters, error codes or 
messages/events). 

The MBMS protocol configuration options is a type 4 information element with a minimum length of 3 octets and a 
maximum length of 253 octets. 

The MBMS protocol configuration options information element is coded as shown in figure 10.5.156/3GPP TS 24.008 
and table 10.5.170/3GPP TS 24.008. 



octet 1 
octet 2 
octet 3 



Figure 10.5.156/3GPP TS 24.008: MBMS protocol configuration options information element 



8 7 6 5 4 


3 


2 1 


MBMS protocol configuration 


options 


lEI 1 


Length of MBMS protocol configuration options contents 



Spare 









Table 10.5.170/3GPP TR 24.008: MBMS protocol configuration options information element 



Bits 1 to 8 of octet 3 are spare and shall be coded as "0". 

NOTE: The reason for defining the Information element is to have a transparent 
mechanism in the SGSN available from the introduction of MBMS. This 
will ensure that MS - GGSN communication is possible if new MBMS 

bearer service related parameters are defined. 



1 0.5.6.1 6 Enhanced network service access point identifier 

The purpose of the Enhanced network service access point identifier information element is to identify the service 
access point that is used at layer 3. 

The Enhanced network service access point identifier is a type 3 information element with a length of 2 octets. 

The value part of an Enhanced network service access point identifier information element is coded as shown in 
figure 10.5.157/3GPP TS 24.008 and table 10.5.171/3GPP TS 24.008. 



£75/ 



3GPP TS 24.008 version 10.10.0 Release 10 



563 



ETSI TS 124 008 VI 0.1 0.0 (2013-04) 



Enhanced NSAPI lEI 



Enhanced NSAPI 
value 



octet 1 
octet 2 



Figure 10.5.157/3GPP TS 24.008: Enhanced network service access point identifier 'information 

element 

Table 10.5.171/3GPP TS 24.008: Entranced network service access point identifier information 

element 



Enhanced NSAPI value (octet 2, bits 1 to 7) 

Bits 

8 7 6 5 4 3 2 1 



00000000 
through 

11111 11 

1 

through 
11111110 



11111111 



Reserved 

Reserved 

NSAPI 128 for Multimedia Broadcast/IVIulticast 
Service (MBMS) Multicast mode 

NSAPI 254 for Multimedia Broadcast/Multicast 
Service (MBMS) Multicast mode 

Reserved (NOTE) 



NOTE: NSAPI 255 is reserved for use by lower layers in the point-to-point radio bearer 

allocation message for Multimedia Broadcast/Multicast Service (MBMS) 
Broadcast mode (see 3GPP TS 25.331 [23c]). 



10.5.6.17 Request type 

The purpose of the Request type information element is to indicate whether the MS requests to estabHsh a new 
connectivity to a PDN or keep the connection(s) to which it has connected via non-3GPP access. 

The Request type information element is also used to indicate that the MS is requesting connectivity to a PDN that 
provides emergency bearer services. 

The Request type information element is coded as shown in figure 10.5.158/3GPP TS 24.008 and 
table 10.5.173/3GPP TS 24.008. 

The Request type is a type 1 information element. 



octet 1 



Request type lEI 



Spare 


Request type value 



Figure 10.5.158/3GPP TS 24.008: Request type information element 
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Table 1 0.5.1 73/3GPP TS 24.008: Request type information element 



Request type value (octet 1 ) 


Bits 




3 2 1 




1 


initial request 


1 


Handover 


1 1 


Unused. If received, the network shall interpret this as "initial request". 


1 


emergency 


All other val 


ues are reserved. 


Bit 4 of octet 1 is spare and shall be coded as zero. 



10.5.6.18 Notification indicator 

The purpose of the Notification indicator information element is to inform the MS about an event which is relevant for 
the upper layer using a PDP context or having requested a session management procedure. 

The Notification indicator information element is coded as shown in figure 10.5.159/3GPP TS 24.008 and 
table 10.5.174/3GPP TS 24.008. 

The Notification indicator is a type 4 information element with 3 octets length. 



Notification indicator lEI 



Length of notification indicator contents 



Notification indicator value 



octet 1 
octet 2 
octet 3 



Figure 1 0.5.1 59/3GPP TS 24.008: Notification indicator information element 
Table 1 0.5.1 74/3GPP TS 24.008: Notification indicator information element 



Notification indicator value (octet 3) 

Bits 

8 7 6 5 4 3 2 1 

1 



10 

to 
1111111 

All other values are reserved. 



SRVCC handover cancelled, IMS session re- 
establishment required (see 3GPP TS 23.216 [126]) 



Unused, shall be ignored if received by the IVIS 



10.5.6.19 Connectivity type 



The purpose of the Connectivity type information element is to specify the type of connectivity selected by the network 
for the PDN connection. 

The Connectivity type information element is coded as shown in figure 10.5.6. 19-1/3GPP TS 24.008 and 
table 10.5.6. 19-1/3GPP TS 24.008. 

The Connectivity type is a type 1 information element. 
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10.5.7.1 



Connectivity type 
lEI 



Connectivity type 
value 



octet 1 



Figure 10.5.6.19-1/3GPP TS 24.008: Connectivity type information element 
Table 10.5.6.19-1/3GPP TS 24.008: Connectivity type information element 



Connectivity type value (octet 1) 

Bits 

4321 

The PDN connection type is not indicated 

1 The PDN connection is considered a LIPA PDN connection 

All other values shall be interpreted as "the PDN connection type is not 
indicated". 



10.5.7 GPRS Common information elements 



PDP context status 



The purpose of the PDP context status information element is to indicate the state of each PDP context which can be 
identified by NSAPI. 

The PDP context status information element is a type 4 information element with 4 octets length. 

The PDP context status information element is coded as shown in figure 10.5.148/3GPP TS 24.008 and 
table 10.5.164/3GPP TS 24.008. 



8 


7 6 5 4 3 2 


1 




PDP context status IE! 


octet 1 


Length of PDP context status contents 


Octet 2 


NSAPI 

(7) 


NSAPI 

(6) 


NSAPI 

(5) 


NSAPI 

(4) 


NSAPI 

(3) 


NSAPI 

(2) 


NSAPI 

(1) 


NSAPI 
(0) 


octet 3 


NSAPI 

(15) 


NSAPI 
(14) 


NSAPI 

(13) 


NSAPI 
(12) 


NSAPI 
(11) 


NSAPI 

(10) 


NSAPI 

(9) 


NSAPI 

(8) 


octet 4 



Figure 10.5.148/3GPP TS 24.008 PDP context status information element 



Table 10.5.164/3GPP TS 24.008: PDP context status information element 



NSAPI(x) shall be coded as follows: 

NSAPI(O) - NSAPI(4): 

are coded as '0' and shall be treated as spare in this version of the protocol. 
NSAPI(5)-NSAPI(15): 

indicates that the SIVI state of the corresponding PDP context is PDP-INACTIVE. 

1 Indicates that the SM state of the corresponding PDP context is not PDP-INACTIVE. 



10.5.7.2 Radio priority 

The purpose of the radio priority information element is to specify the priority level that the MS shall use at the lower 
layers for transmission of data related to a PDP context or for mobile originated SMS transmission. 
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The radio priority information element is coded as shown in figure 10.5.145/3GPP TS 24.008 and 
table 10.5.161/3GPP TS 24.008. 

The radio priority is a type 1 information element. 



1 

octet 1 

Figure 10.5.145/3GPP TS 24.008: Rad/o pr/of/fy information element 
Table 10.5.161/3GPP TS 24.008: Bad/opf/of/fy information element 



Radio priority IE! 



spare 


Radio priority 
level value 



Radio priority level value (octet 1 ) 

Bits 

321 




001 
01 
01 1 
1 00 


priority level 1 (highest) 
priority level 2 
priority level 3 
priority level 4 (lowest) 




All other values are interpreted as 
the protocol. 


priority level 4 by this version of 



10.5.7.3 



GPRS Timer 



The purpose of the GPRS timer information element is to specify GPRS specific timer values, e.g. for the READY 
timer. 

The GPRS timer is a type 3 information element with 2 octets length. 

The GPRS timer information element is coded as shown in figure 10.5.146/3GPP TS 24.008 and table 10.5.172/3GPP 
TS 24.008. 



octet 1 
octet 2 



Figure 10.5.146/3GPP TS 24.008: GPRS T/mer information element 



8 


7 


6 


5 4 3 2 


1 


GPRS Timer IE! | 




Unit 




Timer value 
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Table 1 0.5.1 72/3GPP TS 24.008: GPRS T/mer information element 



Timer value (octet 2) 

Bits 5 to 1 represent the binary coded timer value. 

Bits 6 to 8 defines the timer value unit for the GPRS timer as follows: 

Bits 

876 

value is incremented in multiples of 2 seconds 

1 value is incremented in multiples of 1 minute 

1 value is incremented in multiples of decihours 

1 1 1 value indicates that the timer is deactivated. 

Other values shall be interpreted as multiples of 1 minute in this version of the 
protocol. 



10.5.7.4 



GPRS Timer 2 



The purpose of the GPRS timer 2 information element is to specify GPRS specific timer values, e.g. for the timer T3302 
or timer T33 19. 

The GPRS timer 2 is a type 4 information element with 3 octets length. 

The GPRS timer 2 information element is coded as shown in figure 10.5. 147/3GPP TS 24.008 and table 10.5. 163/3GPP 
TS 24.008. 



GPRS Timer 2 lEI 



Length of GPRS Timer 2 contents 



GPRS Timer 2 value 



octet 1 
octet 2 
octet 3 



Figure 10.5.147/3GPP TS 24.008: GPRS T/mer 2 information element 
Table 1 0.5.1 63/3GPP TS 24.008: GPRS T/mer 2 information element 



GPRS Timer 2 value is coded as octet 2 of the GPRS f/mer information element. 



10.5.7.4a GPRS Timer 3 

The purpose of the GPRS timer 3 information element is to specify GPRS specific timer values, e.g. for the 
timer T3396. 

The GPRS timer 5 is a type 4 information element with 3 octets length. 

The GPRS timer 3 information element is coded as shown in figure 10.5. 147 a/3GPP TS 24.008 and 
table 10.5.163a/3GPP TS 24.008. 



8 


7 6 5 4 3 2 


1 


GPRS Timer 3 lEI 


Length of GPRS Timer 3 contents 


Unit Timer value 



octet 1 
octet 2 
octet 3 



Figure 1 0.5.1 47a/3GPP TS 24.008: GPRS T/'mer 3 information element 
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Table 1 0.5.1 63a/3GPP TS 24.008: GPRS T/mer 3 information element 



GPRS Timer 3 value (octet 3) 

Bits 5 to 1 represent tine binary coded timer value. 

Bits 6 to 8 defines the timer value unit for tfie GPRS timer as follows: 

Bits 

876 

value is incremented in multiples of 10 minutes 

1 value is incremented in multiples of 1 hour 

1 value is incremented in multiples of 10 hours 

1 1 value is incremented in multiples of 2 seconds 

1 value is incremented in multiples of 30 seconds 
1 1 value is incremented in multiples of 1 minute 

1 1 1 value indicates that the timer is deactivated. 

Other values shall be interpreted as multiples of 1 hour in this version of the 
protocol. 



10.5.7.5 Radio priority 2 

The purpose of the radio priority 2 information element is to specify the priority level that the MS shall use at the lower 
layers for transmission of mobile originated TOMS transmission. 



The radio priority 2 information element is coded as shown in figure 10.5. 148/3GPP TS 24.008 and 
table 10.5.164/3GPP TS 24.008. 

The radio priority is a type 1 information element. 



8 


7 6 


5 


4 


3 2 1 


Radio priority 2 lEI 



spare 


Radio priority 
level value 



octet 1 

Figure 10.5.148/3GPP TS 24.008: Radio pr/or/fy 2 information element 
Table 10.5.164/3GPP TS 24.008: Rad/opr/of/Yy 2 information element 



Radio priority level value (octet 1 , bits 1 -3) 



Bits 

3 2 1 

1 

1 

1 1 

1 



priority level 1 (highest) 
priority level 2 
priority level 3 
priority level 4 (lowest) 



All other values are interpreted as priority level 4 by this version of the protocol. 



10.5.7.6 



MBMS context status 



The purpose of the MBMS context status information element is to indicate the state of each MBMS context which can 
be identified by an NSAPI. 
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The MBMS context status information element is a type 4 information element with a minimum length of 2 octets and a 
maximum length of 18 octets. 

The MBMS context status information element is coded as shown in figure 10.5.149/3GPP TS 24.008 and 
table 10.5.165/3GPP TS 24.008. 



8 


7 6 5 4 3 2 


1 1 


MBMS context status lEI 


Length of MBMS context status contents 


NSAPI 
(135) 


NSAPI 

(134) 


NSAPI 
(133) 


NSAPI 
(132) 


NSAPI 

(131) 


NSAPI 
(130) 


NSAPI 
(129) 


NSAPI 
(128) 


NSAPI 

(143) 


NSAPI 

(142) 


NSAPI 
(141) 


NSAPI 

(140) 


NSAPI 

(139) 


NSAPI 
(138) 


NSAPI 

(137) 


NSAPI 
(136) 



NSAPI 

(255) 


NSAPI 
(254 


NSAPI 
(253) 


NSAPI 
(252) 


NSAPI 

(251) 


NSAPI 
(250) 


NSAPI 
(249) 


NSAPI 
(248) 



octet 1 
octet 2 
octet 3 

octet 4 



octet 1 8 



Figure 10.5.149/3GPP TS 24.008 MBMS context status information element 
Table 10.5.165/3GPP TS 24.008: MBMS context status information element 



For X = 128 to 255, NSAPI(x) shall be coded as follows: 

indicates that the SM state of the corresponding MBMS context is PDP-INACTIVE. 

1 indicates that the SM state of the corresponding MBMS context is not PDP-INACTIVE. 

If octets are not included in the information element, the receiver shall interprete the NSAPI(x) values of these 
octets as set to 0. 



10.5.7.7 Uplink data Status 

The purpose of the Uplink data status information element is to indicate to the network which preserved PDP contexts 
have uplink data pending. 

The Uplink data status information element is a type 4 information element with 4 octets length. 

The Uplink data status information element is coded as shown in figure 10.5.149/3GPP TS 24.008 and 
table 10.5.166/3GPP TS 24.008. 



octet 1 
octet 2 
octet 3 

octet 4 



Figure 1 0.5.1 49A/3GPP TS 24.008 Uplink data status information element 



8 


7 6 5 4 3 2 


1 1 


Uplink data status lEI 


Length of Uplink data status contents 


NSAPI 

(7) 


NSAPI 

(6) 


NSAPI 

(5) 


Spare 

(0) 


Spare 
(0) 


Spare 

(0) 


Spare 
(0) 


Spare 
(0) 


NSAPI 

(15) 


NSAPI 

(14) 


NSAPI 

(13) 


NSAPI 
(12) 


NSAPI 
(11) 


NSAPI 

(10) 


NSAPI 

(9) 


NSAPI 

(8) 
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Table 1 0.5.1 66/3GPP TS 24.008: Uplink data status information element 



NSAPI uplinl< status (octet 3 and 4) 

Octet 3, bits 1 to 5 are all spare and shall be encoded as 

NSAPI(5) - NSAPI(15) (octets 3 - 4): 

no uplink data are pending for the preserved PDP context or the PDP context is PDP-INACTIVE or is 
PDP-ACTIVE with a RAB already established. 

1 uplink data are pending for the preserved PDP context. 



10.5.7.8 Device properties 

The purpose of the Device properties information element is to indicate if the MS is configured for NAS signalling low 
priority. The network uses the Device properties information element for core-network congestion handling and for 
charging purposes. 

The Device properties information element is coded as shown in figure 10.5.7.8. 1/3GPP TS 24.008 and 
table 10.5.7.8. 1/3GPP TS 24.008. 

The Device properties is a type 1 information element. 



Device properties 
IE! 



Spare 



Spare 



Spare 


Low 
priority 



octet 1 

Figure 10.5.7.8.1/3GPP TS 24.008: Device properties information element 
Table 10.5.7.8.1/3GPP TS 24.008: Device properties information element 



Low priority (octet 1 ) 



Bit 
1 


1 



MS is not configured for NAS signalling low priority 
IVIS is configured for NAS signalling low priority 



The value "0" can also be used by an IVIS configured for NAS signalling low priority for 
the exception cases specified in subclause 1 .8. 

Bits 2, 3 and 4 of octet 1 are spare and shall be coded as zero. 
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1 1 List of system parameters 

The description of timers in the following table should be considered a brief summary. The precise details are found in 
clauses 3 to 6, which should be considered the definitive descriptions. 

11.1 Timers and counters for radio resource management 

See 3GPPTS 44.018 [84]. 

11.2 Timers of mobility management 

Table 11. 1/3GPP TS 24.008: Mobility management timers - IVIS-side 



TIMER 


MM 


TIME 


CAUSE FOR START 


NORMAL STOP 


AT THE EXPIRY 


NUM. 


STATE 


OUT 
VAL. 








T3210 




20s 


- LOC_UPD_REQ 


- LOC UPD ACC 






LOCATION UPDATING 




sent 


- LOC UPD REJ 






INITIATED 






- AUTH_REJ 

- Lower layer failure 


Start T321 1 


T3211 




15s 


- LOC_UPD_REJ with 


- cell change 


Restart the 




MM IDLE, 




cause#1 7 netw. 


- request for MM 


Location update 








failure 


connection 


proc. 








- lower layer failure or 


establishment 










RR conn, released 


- change of LA 










after RR conn, abort 












during loc. updating 






T3212 




Note1 


- termination of MM 


- initiation of MM service 


initiate periodic 




MM IDLE 




service or MM 
signalling 


or MM signalling 


updating 


T3213 




4s 


- location updating 


- change of BCCH 


new random 




LOCATION UPDATING 




failure 


parameter 


attempt 




INITIATED 










T3214 




20s 


AUTHENT FAILURE 


AUTHENT REQ received 


Consider the 




LOCATION UPDATING 




Cause = 'MAC failure' 




networl< as 'false' 




INITIATED 




or 'GSM 
authentication 




(see 4.3.2.6.1) 




WAIT FOR OUTGOING 




unacceptable' sent 








MM CONNECTION 












IMSI DETACH INITIATED 










T3216 




15s 


AUTHENT FAILURE 


AUTHENT REQ received 


Consider the 




LOCATION UPDATING 




Cause = Synch failure 




networl< as 'false' 




INITIATED 




sent 




(see 4.3.2.6.1) 




WAIT FOR OUTGOING 












MM CONNECTION 












IMSI DETACH INITIATED 










T3218 




20s 


RAND and RES 


- Cipher mode setting 


Delete the stored 




LOCATION UPDATING 




stored as a result of 


(A/Gb mode only) 


RAND and RES 




INITIATED 




of a UMTS 
authentication 


Security mode 
setting (lu mode only) 






WAIT FOR OUTGOING 




challenge 


- CM_SERV_ACCEPT 






MM CONNECTION 






received 
- CM SERVICE 






IMSI DETACH INITIATED 






REJECT received 

- LOCATION UPDATING 
ACCEPT received 

- AUTHENT REJ 
received 

- AUTHENT FAIL sent 

- enter MM IDLE or NULL 
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T3220 


IMSI DETACH INITIATED 


5s 


- IMSI DETACH 


- release from RM- 
sublayer 


enter Null or Idle, 
ATTEMPTING TO 
UPDATE 


T3230 


WAIT FOR OUTGOING 
MM CONNECTION 

WAIT FOR ADDITIONAL 

OUTGOING MM 

CONNECTION 

WAIT FOR 
REESTABLISH 


15s 


- CM SERV REQ 
CM RE-EST REQ 


- Cipher mode setting 

- CM SERV REJ 

- CM SERV ACC 


provide release 
ind. 


T3240 


WAIT FOR NETWORK 
COMMAND 

LOCATION UPDATE 
REJECTED 


10s 


see subclause 11.2.1 


see subclause 11.2.1 


abort the RR 
connection 


T3241 


RR CONNECTION 

RELEASE NOT 

ALLOWED 


300s 


see subclause 11.2.1 


see subclause 11.2.1 


abort the RR 
connection 


T3242 


All except NULL 


12 
hours 


eCall only MS enters 
MM IDLE state after 
an emergency call 


- Removal of eCall only 
restriction 


Perform eCall 
Inactivity 
procedure in 
subclause 4.4.7 


T3243 


All except NULL 


12 
hours 


eCall only MS enters 
MM IDLE state after 
a 

test/reconfiguration 
call 


- Removal of eCall only 
restriction 


Perform eCall 
Inactivity 
procedure in 
subclause 4.4.7 


T3245 


All except NULL 


Note 2 


see subclause 4.1.1.6 
(A/Gb or lu mode 
only) 

see subclause 5.3.7a 
in3GPPTS 
24.301 [120] (SI 
mode only) 


- SIM/USIM is removed 


see subclause 
4.1.1.6 (A/Gb or lu 
mode only) 
see subclause 
5.3.7a in 3GPP 
TS 24.301 [120] 
(SI mode only) 


T3246 


LOCATION UPDATING 
INITIATED 

WAIT FOR OUTGOING 
MM CONNECTION 

WAIT FOR ADDITIONAL 

OUTGOING MM 

CONNECTION 

WAIT FOR 
REESTABLISH 


Note 3 


LOC UPD REJor 
CM SERV REJ 
received with a timer 
value for T3246; 
"Extended wait time" 
for CS domain from 
the lower layers 


- paging 


Restart the 
Location update 
procedure or CM 
service request 
procedure, 
dependent on MM 
state and update 
status 


NOTE 1 : The timeout value is broadcasted in a SYSTEM INFORMATION message. 

NOTE 2: The MS starts the timer with a random value, uniformly drawn from the range between 24h and 48h. 

NOTE 3: The timer value is provided by the network in an LOCATION UPDATE REJECT or CM SERVICE REJECT 

message or as a "Extended wait time" value by the lower layers, or chosen randomly from a default value 

range of 15 - 30 minutes. 
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Table 11.2/3GPP TS 24.008: Mobility management timers - network-side 



TIMER 
NUM. 


MM 
STATE 


TIME 
OUT 
VAL. 


CAUSE FOR 
START 


NORMAL STOP 


AT THE EXPIRY 


AT THE 

SECOND 

EXPIRY 


T3250 


TMSI 

REALLOCATION 

INITIATED 


12s 


TMSI-REAL-CMD 
or LOC UPD 
ACC with new 
TIVISI sent 


TMSI-REALL- 
COIVI received 


Optionally 
Release RR 
connection 




T3255 




Note 
2 


LOC UPD ACC 

sent with"Follow 
on Proceed" 


CM SERVICE 
REQUEST 


Release RR 
Connection or use 
for mobile station 
terminating call 




T3260 


AUTHENTICATION 
INITIATED 


12s 


AUTHENT- 
REQUESTsent 


AUTHENT- 
RESPONSE 
received 

AUTHENT- 
FAILURE 
received 


Optionally 
Release RR 
connection 




T3270 


IDENTIFICATION 
INITIATED 


12s 


IDENTITY 
REOUEST sent 


IDENTITY 
RESPONSE 
received 


Optionally 
Release RR 
connection 





NOTE 2: The value of this timer is not specified by this recommendation. 

11.2.1 Timer T3240 and Timer T3241 

Timer T3240 is started in the mobile station when: 

the mobile station receives a LOCATION UPDATING ACCEPT message completing a location updating 
procedure in the cases specified in subclauses 4.4.4.6 and 4.4.4.8; 

the mobile station receives a LOCATION UPDATING REJECT message in the cases specified in 
subclause 4.4.4.7; 

the mobile station has sent a CM SERVICE ABORT message as specified in subclause 4.5. L7; 

the mobile station has released or aborted all MM connections in the cases specified in 4.3.2.5, 4.3.5.2, 4. 5. LI, 
and 4.5.3. L 

Timer T3240 is stopped, reset, and started again at receipt of an MM message. 

Timer T3240 is stopped and reset (but not started) at receipt of a CM message that initiates establishment of an CM 
connection (an appropriate SETUP, REGISTER, or CP-DATA message as defined in 3GPP TS 24.008, 3GPP TS 
24.010 [21] or 3GPPTS 24.011 [22]). 

Timer T3241 is started in the mobile station when entering MM state RR CONNECTION RELEASE NOT 
ALLOWED. 

Timer T3241 is stopped and reset (but not started) when the MM state RR CONNECTION RELEASE NOT 
ALLOWED is left. 

If timer T3241 expires, the MS shall abort the RR connection and enter the MM state MM IDLE. 
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1 1 .2.2 Timers of GPRS mobility management 

Table 11. 3/3GPP TS 24.008: GPRS Mobility management timers - MS side 



TIMER 


TIMER 


STATE 


CAUSE OF START 


NORMAL STOP 


ON THE 


NUM. 


VALUE 








^st 2nd 3rd 4'^ 
EXPIRY Note 3 


T3310 


15s 


GMM- 


ATTACH REQ sent 


ATTACH ACCEPT 


Retransmission of 






REG-INIT 




received 

ATTACH REJECT 
received 


ATTACH REQ 


T3311 


15s 


GMM-DEREG 


ATTACH REJ with other cause 


Change of the 


Restart of the 






ATTEMPTING 


values as described in chapter 


routing area 


Attach or the RAU 






TO ATTACH or 


'GPRS Attach' 


lu mode - PMM 


procedure with 






GMM-REG 


ROUTING AREA UPDATE REJ 


CONNECTED 


updating of the 






ATTEMPTING 


with other cause values as 


mode entered 


relevant attempt 






TO UPDATE 


described in chapter 'Routing 


(Note 1) 


counter 






GMM-REG 


Area Update' 


A/Gb mode - 








NORMAL 


Low layer failure 


READY timer is 








SERVICE 




started (Note 1) 




T3316 


30s 


GMM- 


RAND and RES stored as a result 


Security mode 


Delete the stored 






REG-INIT 


of a UMTS authentication 


setting 


RAND and RES 






GMM-REG 


challenge 


(lu mode only) 








GMM-DEREG- 
INIT 




SERVICE ACCEPT 
received, (lu mode 
only) 

SERVICE REJECT 

received 

(lu mode only) 

ROUTING AREA 
UPDATE ACCEPT 








GMM-RA- 
UPDATING-INT 

GMM-SERV- 

REQ-INIT 
(lu mode only) 














received 












AUTHENTICATION 












AND CIPHERING 












REJECT received 












AUTHENTICATION 












AND CIPHERING 












FAILURE sent 












Enter GMM- 












DEREG or 












GMM-NULL 




T3318 


20s 


GMM- 


AUTHENTICATION & 


AUTHENTICATION 


On first expiry, the 






REG-INIT 


CIPHERING FAILURE 


& CIPHERING 


MS should consider 






GMM-REG 
GMM-DEREG- 


(cause='MAC failure' or 'GSM 
authentication unacceptable') sent 


REOU EST received 


the network as false 
and will follow 
subclause 4.7.7.6.1, 






INIT 






if the MS is not 






GMM-RA- 






attached for 






UPDATING-INT 






emergency bearer 






GMM-SERV- 






services. 






REQ-INIT(lu 






On the first expiry, 






mode only) 






the MS will follow 
subclause 4.7.7.6, 
under "for items f 
and g", if the MS is 
attached for 
emergency bearer 
services. 
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T3320 


15s 


GMM- 


AUTHENTICATION & 


AUTHENTICATION 


On first expiry, the 






REG-INIT 


CIPHERING FAILURE 


& CIPHERING 


IVIS should consider 






GMM-REG 
GMM-DEREG- 


(cause=synch failure) sent 


REQUEST received 


the network as false 
and will follow the 
subclause 4.7.7.6.1, 






INIT 






If the IVIS is not 






GMM-RA- 






attached for 






UPDATING-INT 






emergency bearer 






GMM-SERV- 

REQ-INIT(lu 

mode only) 






services. 

On the first expiry, 
the MS will follow 
subclause 4.7.7.6, 
under "for items f 
and g", if the MS is 
attached for 
emergency bearer 
services. 


T3321 


15s 


GMM- 


DETACH REQ sent 


DETACH ACCEPT 


Retransmission of 






DEREG-INIT 




received 


the DETACH REQ 


T3330 


15s 


GMM- 


ROUTING AREA UPDATE 


ROUTING AREA 


Retransmission of 






ROUTING- 


REOUEST sent 


UPDATE ACC 


the ROUTING 






UPDATING- 




received 


AREA UPDATE 






INITIATED 




ROUTING AREA 
UPDATE REJ 
received 


REQUEST 
message 


T3340 


10s 


GMM- 


ATTACH REJ, DETACH REQ, 


PS signalling 


Release the PS 


(lu mode 
only) 




REG-INIT 


ROUTING AREA UPDATE REJ or 


connection released 


signalling 




GMM-DEREG- 
INIT 


SERVICE REJ with any of the 
causes#11,#12, #13,#15, or 




connection and 
proceed as 






GMM-RA- 
UPDATING-INT 

GMM-SERV- 

REQ-INIT(lu 

mode only) 


#25. 

ATTACH ACCEPT or ROUTING 
AREA UPDATE ACCEPT is 
received with "no follow-on 
proceed" indication. 

DETACH ACCEPT received after 




described in 
subclause 4.7.1.9 






GMM- 
Al IbMPTING- 
TO-UPDATE- 

MM 


the MS sent DETACH REQUEST 
with detach type to "IIVISI detach" 
while the T3346 timer is running 










GMM-REG- 












NORMAL- 












SERVICE 








NOTE 1 : The conditions for which this applies are described in subclause 4.7.5.1 .5. 
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Table 11. 3a/3GPP TS 24.008: GPRS Mobility management timers - IVIS side 



TIMER 
NUM. 


TIMER 
VALUE 


STATE 


CAUSE OF START 


NORMAL STOP 


ON 
EXPIRY 


T3302 


Default 12 
min 

Notel 

Notes 


GMM-DEREG 

or 

GMM-REG 


At attach failure and the attempt 
counter Is greater than or equal 
to 5. 

At routing area updating failure 
and the attempt counter is greater 
than or equal to 5. 


At successful attach 

At successful 
routing area 
updating 


On every expiry, 
initiation of the 

GPRS attach 
procedure 

or 

RAU procedure 


1331 2 


Default 
54 min 

Notel 


GMM-REG 


In A/Gb mode, when READY state 
is left. 

In lu mode, when PMM- 
CONNECTED mode is left. 


When entering state 
GMM-DEREG 


Initiation of the 
Periodic RAU 
procedure if the MS 
is not attached for 
emergency bearer 
services. 

Implicit detach from 
network if the MS is 
attached for 
emergency bearer 
services. 


T3314 

READY 

(A/Gb 
mode only) 


Default 
44 sec 
Note 2 


All except GMM- 
DEREG 


Transmission of a PTP PDU 


Forced to Standby 


No cell-updates are 
performed 


T3317 

(lu mode 
only) 


15s 


GMM- 
SERVICE- 
REQUEST- 
INITIATED 


SERVICE REQ sent 


Security mode 
control procedure is 
completed, 

SERVICE ACCEPT 
received, or 

SERVICE REJECT 
received 


Abort the procedure 


1331 9 

(lu mode 
only) 


Default 
30s 

Note 1 

Note 4 


GMM-REG 


Completion of the Security Mode 
Control procedure after sending a 
SERVICE REQUEST with service 
type "data". 

Reception of a SERVICE 
ACCEPT message. 


When entering 
PMM-IDLEmode. 

When the radio 
access bearer is 
released for any 
active PDP context. 

When entering state 
GMM-DEREG 


SERVICE REO with 
service type "data" 
may be invoked 
again, if required. 


T3323 


NOTE 6 


GMM- 
REGISTERED 


T3312 expires while the MS is in 
GMM-REGISTERED.NO-CELL- 
AVAILABLE and ISR is activated. 


When entering state 

GMM- 

DEREGISTERED 

or when entering 

GMM- 

CONNECTED 

mode. 


Deactivation of ISR 
by setting TIN to 
"GUTI" 
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T3346 


NOTE 7 


GMM- 


ATTACH REJECT, ROUTING 


Paging received 


Initiation of attach 






DEREGISTERE 


AREA UPDATE REJECT or 




procedure, routing 






D. 


SERVICE REJECT received with 




area updating 






Al IbMPTING- 


a timer value for T3346; 




procedure or 






TO-ATTAGH 


"Extended wait time" for PS 




service request 






GMM- 


domain from the lower layers 




procedure. 






REGISTERED. 


(defined in 




dependent on GMM 






Al IbMPTING- 


3GPP TS 25.331 [23c]). 




state and GPRS 






TO-UPDATE 

GMM- 

i~\ 1 — /~» 1 /^~i~i — i~\ 1 — i~\ 


ATTACH REJECT, TRACKING 




update status. 






AREA UPDATE REJECT or 




Initiation of attach 






REGISTERED 


SERVICE REJECT (defined in 




procedure, tracl<ing 






EMM- 


3GPP TS 24.301 [120]) received 




area updating 






DEREGISTERE 


with a timer value for T3346; 




procedure or 






D. 


"Extended wait time" for PS 




service request 






Al IbMPTING- 


domain from the lower layers. 




procedure. 






TO-ATTAGH 


(defined in 3GPP TS 36.331 [22]) 




dependent on EMM 






EMM- 






state and EPS 






REGISTERED. 






update status. 






Al IbMPTING- 






(defined in 






TO-UPDATE 






3GPP TS 24.301 [1 






EMM- 






20]) 






REGISTERED 












(defined in 












3GPP TS 24.30 












1 [120]) 









NOTE 1 : The value of this timer is used if the network does not indicate another value in a GMM signalling 
procedure. 

NOTE 2: The default value of this timer is used if neither the MS nor the Network send another value, or if the 
Network sends this value, in a signalling procedure. 

NOTE 3: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in 
the corresponding procedure description. 

NOTE 4: The purpose of this timer is to prevent the MS from repeating the SERVICE REQUEST message with 
service type "data" too early in case the request to setup the radio access bearer is queued by the radio 
access network. 

NOTE 5: In lu mode, the default value of this timer is used if the network provides a value for this timer in a non- 
integrity protected lu mode GMM message. 

NOTE 6: The value of this timer may be provided by the network to the MS in the ATTACH ACCEPT message 
and ROUTING AREA UPDATE ACCEPT message. The default value of this timer is identical to the 
value of timer T3312. 

NOTE 7: The timer value is provided by the network in an ATTACH REJECT, ROUTING AREA UPDATE 

REJECT, TRACKING AREA UPDATE REJECT or SERVICE REJECT message or as a "Extended wait 
time" value by the lower layers, or chosen randomly from a default value range of 15 - 30 minutes. 
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Table 11.4/3GPP TS 24.008: GPRS Mobility management timers - network side 



TIMER 
NUM. 


TIMER 
VALUE 


STATE 


CAUSE OF START 


NORMAL STOP 


ON THE 

^st 2nd 3rd 4th 

EXPIRY Note 3 


T3322 


6s 


GMM- 
DEREG-INIT 


DETACH REQ sent 


DETACH ACCEPT 
received 


Retransmission of 

DETACH 

REQUEST 


T3350 


6s 


GMM- 
COMMON- 
PROC-INIT 


ATTACH ACCEPT 

sent with P-TMSI and/or TMSI 

RAU ACCEPT sent with P-TMSI 
and/or TMSI 

P-TMSI REALLOC COMMAND 
sent 


ATTACH 

COMPLETE 

received 

RAU COMPLETE 
received 

P-TMSI REALLOC 

COMPLETE 

received 


Retransmission of 
the same message 
type, i.e. ATTACH 
ACCEPT, RAU 
ACCEPT or 
REALLOC 
COMMAND 


T3360 


6s 


GMM- 
COMMON- 
PROC-INIT 


AUTH AND CIPH REQUEST 
sent 


AUTH AND CIPH 

RESPONSE 

received 

AUTHENT-AND 

CIPHER-FAILURE 

received 


Retransmission of 
AUTH AND CIPH 
REQUEST 


T3370 


6s 


GMM- 
COMMON- 
PROC-INIT 


IDENTITY REOUEST sent 


IDENTITY 

RESPONSE 

received 


Retransmission of 

IDENTITY 

REQUEST 



Table 11 .4a/3GPP TS 24.008: GPRS IVIobility management timers - networit side 



TIMER 
NUM. 


TIMER 
VALUE 


STATE 


CAUSE OF START 


NORMAL STOP 


ON 
EXPIRY 


T3313 


Note 1 


GMM_REG 


Paging procedure initiated 


Paging procedure 
completed 


Network dependent 


T3314 

READY 

(A/Gb 

mode only) 


Default 
44 sec 
Note 2 


All except GMM- 
DEREG 


Receipt of a PTP PDU 


Forced to Standby 


The network shall 
page the MS if a 
PTP PDU has to be 
sent to the MS 


Mobile 
Reachable 


Note 4 


All except GMM- 
DEREG 


In A/Gb mode, change from 
READY to STANDBY state 
In lu mode, change from PMM- 
CONNECTED mode to PMM-IDLE 
mode. 


PTP PDU received 


Network dependent 
but typically paging 
is halted on 1st 
expiry if the MS is 
not attached for 
emergency bearer 
services. 

Implicitly detach the 
MS which is 
attached for the 
emergency bearer 
services. 


Implicit 

Detach 

timer 


Notes 


All except GMM- 
DEREG 


The Mobile Reachable timer 
expires while the network is in 
PMM-IDLE mode or STANDBY 
state. 


PTP PDU received 


Implicitly detach the 
MS on 1st expiry 



NOTE 1 : The value of this timer is network dependent. 

NOTE 2: The defauh value of this timer is used if neither the MS nor the Network send another value, or if the 

Network sends this value, in a signalling procedure. The value of this timer should be slightly shorter in 
the network than in the MS, this is a network implementation issue. 
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NOTE 3: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in 
the corresponding procedure description. 

NOTE 4: The default value of this timer is 4 minutes greater than T33 12. If T3346 is larger than T33 12 and the 
SGSN includes timer T3346 in the ROUTING AREA UPDATE REJECT message or the SERVICE 
REJECT message, the value of the Mobile Reachable timer is 4 minutes greater than T3346. If the MS is 
attached for emergency bearer services, the value of this timer is set equal to T3312. 

NOTE 5: The value of this timer is network dependent. If ISR is activated, the default value of this timer is 4 
minutes greater than T3323. 
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1 1 .2.3 Timers of GPRS session management 

Table 11.2c/3GPP TS 24.008: GPRS session management timers - lUIS side 



TIMER 
NUM. 


TIMER 
VALUE 


STATE 


CAUSE OF START 


NORMAL STOP 


ON THE 

^st 2nd 3rd 4th 

EXPIRY 


T3380 


30s 


PDP- 
ACTIVE-PEND 
or IVIBIVIS 
ACTIVE- 
PENDING 


ACTIVATE PDP CONTEXT 
REQUEST, ACTIVATE 
SECONDARY PDP CONTEXT 
REQUEST or ACTIVATE MBMS 
CONTEXT REQUEST sent 


ACTIVATE 
PDP CONTEXT 
ACCEPT, 
ACTIVATE 
SECONDARY PDP 
CONTEXT 
ACCEPT or 
ACTIVATE MBMS 
CONTEXT 
ACCEPT received 

ACTIVATE 
PDP CONTEXT 
REJECT, 
ACTIVATE 
SECONDARY PDP 
CONTEXT 
REJECT or 
ACTIVATE MBMS 
CONTEXT 
REJECT received 


Retransmission of 
ACTIVATE PDP 
CONTEXT REQ, 
ACTIVATE 
SECONDARY PDP 
CONTEXT 
REQUEST or 
ACTIVATE MBMS 
CONTEXT 
REQUEST 


T3381 


8s 


PDP-MODIFY- 
PENDING 


MODIFY PDP CONTEXT 
REQUEST sent 


MODIFY PDP 
CONTEXT 
ACCEPT received 


Retransmission of 
MODIFY PDP 
CONTEXT 
REQUEST 


T3390 


8s 


PDP- 
INACT-PEND 


DEACTIVATE PDP CONTEXT 
REQUEST sent 


DEACTIVATE PDP 
CONTEXT ACC 
received 


Retransmission of 
DEACTIVATE 
PDP CONTEXT 
REQUEST 


T3396 


N0TE1 


PDP- 
ACT-PEND or 
MBMS ACTIVE- 
PENDING 

PROCEDURE 

TRANSACTION 

PENDING 

(defined in 

3GPP TS 24.301 

[120]) 


ACTIVATE PDP CONTEXT 
REJECT, ACTIVATE MBMS 
CONTEXT REJECT, ACTIVATE 
SECONDARY PDP CONTEXT 
REJECT or MODIFY PDP 
CONTEXT REJECT with a timer 
value for T3396 received 

PDN CONNECTIVITY REJECT, 
BEARER RESOURCE 
MODIFICATION REJECT or 
BEARER RESOURCE 
ALLOCATION REJECT (defined 
in 3GPP TS 24.301 [120]) with a 
timer value for T3396 received 


REQUEST PDP 
CONTEXT 
ACTIVATION or 
REQUEST 
SECONDARY PDP 
CONTEXT 
ACTIVATION or 
MODIFY PDP 
CONTEXT 
REQUEST or 
ACTIVE DEFAULT 
EPS BEARER 
CONTEXT 
REQUEST or 
ACTIVATE 
DEDICATED EPS 
BEARER 
CONTEXT 
REQUEST or 
MODIFY EPS 
BEARER 
CONTEXT 
REQUEST 
received 


None 
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NOTE 1 : The value of this timer can be provided by the networl< operator when a request to activate a PDP context or 
a request to activate a MBMS context or a request to modify a PDP context is rejected by the networl< with a 
certain SM cause, or a request to establish a PDN connection, a request to allocate bearer resources or a 
request to modify bearer resources (defined in 3GPP TS 24.301 [120]) is rejected by the network with a 
certain ESM cause. The value of the timer when included with SM cause or ESM cause #26 is taken 
randomly from an operator dependent range not greater than 72 hours. If the PDN CONNECTIVITY REJECT 
was sent together with an ATTACH REJECT message and the ATTACH REJECT message was not integrity 

protected, MS uses a random value from a default range of 15mins to SOmins. 



NOTE: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in 
the corresponding procedure description. 

Table 11. 2d/3GPP TS 24.008: GPRS session management timers - network side 



TIMER 


TIMER 


STATE 


CAUSE OF START 


NORMAL STOP 


ON THE 


NUM. 


VALUE 








^st 2nd 3rd 4th 
EXPIRY 


T3385 


8s 


PDP- 


REOUEST PDP CONTEXT 


ACTIVATE PDP 


Retransmission of 






ACT-PEND or 


ACTIVATION or 


CONTEXT 


REOUEST PDP 






MBMS ACTIVE- 


REOUEST SECONDARY PDP 


REQUEST or 


CONTEXT 






PENDING 


CONTEXT ACTIVATION or 


ACTIVATE 


ACTIVATION or 








REOUEST MBMS CONTEXT 


SECONDARY PDP 


REOUEST 








ACTIVATION sent 


CONTEXT 
REQUEST or 
ACTIVATE MBMS 
CONTEXT 
REQUEST 
received 


SECONDARY PDP 
CONTEXT 
ACTIVATION or 
REOUEST MBMS 
CONTEXT 
ACTIVATION 


T3386 


8s 


PDP- 


MODIFY PDP CONTEXT 


MODIFY PDP 


Retransmission of 






MOD-PEND 


REOUEST sent 


CONTEXT ACC 
received 


MODIFY PDP 
CONTEXT REQ 


T3395 


8s 


PDP- 


DEACTIVATE PDP CONTEXT 


DEACTIVATE PDP 


Retransmission of 






INACT-PEND or 


REOUEST sent 


CONTEXT ACC 


DEACTIVATE PDP 






MBMS 




received 


CONTEXT REQ 






INACTIVE- 












PENDING 









NOTE: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in 
the corresponding procedure description. 
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1 1 .3 Timers of circuit-switched call control 



Table 11.3/3GPP TS 24.008: Call control timers - MS side 



TIM 


TIM 


STATE OF 


CAUSE OF 


NORMAL 


AT FIRST 


AT SECOND 


NUM. 


VAL 


CALL 


START 


STOP 


EXPIRY 


EXPIRY 


T303 


30s 


Call initiated 


CM SER RQ 
sent 


CALL PROC, or 

RELCOMP 

received 


Clear the call 


Timer is not 
restarted 


T305 


30s 


Disconnect 
Request 


DISC sent 


REL or DISC 
received 


REL sent. 


Timer is not 
restarted 


T308 


30s 


Release 
request 


REL sent 


REL COMP or 
REL received 


Retrans. 
RELEASE 
restart T308 


Call ret. release 


T310 


30s 


Outgoing 


CALL PROC 


ALERT,CONN, 


Send DISC 


Timer is not 


Note 




call 


received 


DISC or PROG 




restarted 


1 




Proceeding 




rec. 






T313 


30s 


Connect 
Request 


CONN sent 


CONNect 

ACKnowledge 

received 


Send DISC 


Timer is not 
restarted 


T323 


30s 


Modify 
Request 


MOD sent 


MOD COMP or 
MOD REJ 
received 


Clear the call 


Timer is not 
restarted 


T324 


15s 


Modify 


MOD received 


MOD COMP or 


MOD REJ 


Timer is not 






request 




MOD REJ sent 


with old 

bearer 

capability 


restarted 


T332 


30s 


Wait for 


START CC 


CC-EST. 


Clear the call 


Timer is not 






network info 


sent 


received 




restarted 


T335 


30s 


CC-Est. 


CC-EST 


RECALL 


Clear the call 


Timer is not 






Confirmed 


CONF.sent 


received 




restarted 


T336 


10s 




START DTMF 
sent 


START DTMF 
ACK or START 
DTMF REJECT 
received 


The MS 
considers the 
DTMF 
Procedure 
(for the digit) 
to be 
terminated 


Timer is not 
restarted 


T337 


10s 




STOP DTMF 


STOP DTMF 


The MS 


Timer is not 








sent 


ACK received 


considers the 
DTMF 

procedure (for 
the current 
digit) to be 
terminated 


restarted 



NOTE 1: T310 is not started if progress indicator #1, #2, or #64 has been delivered in the CALL PROCEEDING 
message or in a previous PROGRESS message. 
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Table 11. 4/3GPP TS 24.008: Call control timers - network side 



TIM 
NUM. 


DFT 
TIM 
VAL 


STATE OF 
CALL 


CAUSE FOR 
START 


NORMAL 
STOP 


AT FIRST 
EXPIRY 


AT SECOND 
EXPIRY 


T301 
Note 

1 


Min18 
Os 


Call 
reeeived 


ALERT 
received 


CONN received 


Clear the call 


Timer is not 
restarted 


T303 


Note 2 


Call present 


SETUP sent 


CALL CONF or 

RELCOMP 

reeeived 


Clear the call 


Timer is not 
restarted 


T305 


30s 


Diseonneet 
Indication 


DISC without 
progress 
indie. #8 
sent or 
CCBS 
Possible 


REL or DISC 
reeeived 


Network 

sends 

RELEASE 


Timer is not 
restarted 


T306 


30s 


Diseonneet 
Indication 


DISC with 
progress 
indie. #8 
sent but no 
CCBS 
possible 


REL or DISC 
reeeived 


Stop the tone/ 
announe. 
Send REL 


Timer is not 
restarted 


T308 


Note 2 


Release 
request 


REL sent 


REL COMP or 
REL received 


Retrans. 
RELEASE 
restart T308 


Release call 
reference 


1310 


Note 2 


Incoming 

call 
proceeding 


CALL CONF 
reeeived 


ALERT, CONN 
or DISC 
reeeived 


Clear the call 


Timer is not 
restarted 


T313 


Note 2 


Connect 
Indication 


CON sent 


CON ACK 
reeeived 


Clear the call 


Timer is not 
restarted 


T323 


30s 


Modify 
request 


MOD sent 


MOD COMP or 
MOD REJ 
reeeived 


Clear the call 


Timer is not 
restarted 


T331 


Note 2 


CC Connec. 
Pending 


CM-SERV 
PROMPT 
sent 


START CC 
reeeived 


Clear the call 


Timer is not 
restarted 


T333 


Note 2 


CC-Est. 
Present 


START CC 
reeeived 


CC-EST.CONF 
or REL COMP 
reeeived 


Clear the call 


Timer is not 
restarted 


T334 

Note 

3 


Min 
15s 


CC-Est. 
Confirmed 


RECALL sent 


SETUP 
reeeived 


Clear the call 


Timer is not 
restarted 


T338 


Note 2 


Diseonneet 
indication 


DISC with 
CCBS 
possible 


REL or DISC 
reeeived 


stop any tone/ 
announe. 
Send REL 


Timer is not 
restarted 



NOTE 1: The network may already have applied an internal alerting supervision function; e.g. incorporated within 
call control. If such a function is known to be operating on the call, then timer T301 is not used. 

NOTE 2: These time values are set by the network operator. 

NOTE 3: When applied to the supplementary service CCBS, the timer T334 can either represent the recall timer T4 
or the notification timer TIO (see 3GPP TS 23.093 [88a]). Thus the timer T334 can take two different 
values. 3GPP TS 23.093 [88a] defines the range of these values. 
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Annex A (informative): 

Example of subaddress information element coding 

This annex gives an example of how the Called Party Subaddress IE is encoded to carry subaddress digits that use IA5 
characters. This example is also applicable to the Calling Party Subaddress IE. 



octet 
1 

2 

3 



NOTE 1 : The value of this bit has no significance when the type of subaddress is "NS AP". 

NOTE 2: These bits are spare. 

NOTE 3: The Authority and Format Identifier code 50 (in BCD) indicates that the subaddress consists of IA5 
characters (see ISO standard 8348 AD2). 

NOTE 4: IA5 character as defined in ITU-T Recommendation T.50/ISO 646 and then encoded into two semi-octets 
according to the "preferred binary encoding" defined in X.213/ISO 8348 AD2. (Each character is 
converted into a number in the range 32 to 127 using the ISO 646 encoding with zero parity and the parity 
bit in the most significant position. This number is then reduced by 32 to give a new number in the range 
to 95. The new number is then treated as a pair of decimal digits with the value of each digit being 
encoded in a semi-octet.) 

NOTE 5: the number of IA5 characters in the subaddress may vary, subject to an upper limit of 19 IA5 characters. 



8 


7 6 5 


4 


3 


2 


1 





110 11 

called party subaddress lEI 





1 





1 
Length 


1 


1 


1 

not 
ext 




NSAP 

(X.213/IS0 8348AD2) 


X 

odd/ev 
note 1 






note 2 








10 10 
API (note 3) 








IA5 Character (note 4) 


IA5 Character (note 4) 




IA5 Character (note 4) 
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Annex B (normative): 
Compatibility checking 

B.1 Introduction 

This annex describes the various compatibility checks which shall be carried out to ensure that the best matched MS and 
network capabilities are achieved on a call between a PLMN and the ISDN. 

Three different processes of compatibility checking shall be performed: 

i) at the user-to-network interface on the calling side (see B.2); 

ii) at the network-user interface on the called side (see B.3.2); 

iii) user-to-user (see B 3.3). 

NOTE: In this context and throughout this annex the term "called user" is the end point entity which is explicitly 
addressed. 

For details on the coding of the information required for compatibility checking, see annex C. 



B.2 Calling side compatibility checking 

B.2.1 Compatibility checking of the CM SERVICE REQUEST 
message 

The network shall check if the service requested in the CM SERVICE REQUEST message is permitted for that 
subscriber. 

B.2. 2 Compatibility/Subscription checking of the SETUP message 

At the calling side the network shall check that the basic service(s) requested by the calling MS in the Bearer Capability 
information element(s) match(es) with the basic services provided to that subscriber by the PLMN. If for at least one 
bearer capability information element contained in the SETUP message a mismatch is detected, then the network shall 
proceed as follows: 

if the SETUP message contained two bearer capability information elements for only one of which a mismatch is 
detected, the network shall either: 

under the conditions specified in 3GPP TS 27.001 [36] (e.g. TS 61 and TS 62), accept the SETUP message 
with a CALL PROCEEDING message containing the, possibly negotiated, bearer capability information 
element for which no mismatch is detected, or 

reject the call using one of the causes listed in annex H. 

otherwise the network shall reject the call using one of the causes listed in annex H. 

Network services are described in 3GPP TS 22.002 [3] and 3GPP TS 22.003 [4] as bearer services and teleservices, 
respectively. 



B.3 Called side compatibility checking 

In this clause, the word "check" means that the MS examines the contents of the specified information element. 
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B.3.1 Compatibility checking with addressing information 

If an incoming SETUP message is offered to the MS with addressing information (i.e. sub-address or called party 
number) the following shall occur: 

a) if the MS has a DDI number or a sub-address, then the information in any Called Party BCD Number or any 
Called Party subaddress information elements of the incoming SETUP message shall be checked by the MS 
against the corresponding part of the number assigned to the user (e.g. for DDI) or the user's own sub-address. 

In the cases of a mismatch, the MS shall release the call. In the case of a match, the compatibility checking 
described in B.3.2 and B.3.3 shall be performed. 

b) if the MS has no DDI number and no sub-address, then the Called Party BCD Number and Called Party Sub- 
address information element shall be ignored for the purposes of compatibility checking. The compatibility 
checking described in B.3.2 and B.3.3 shall be performed. 

NOTE: According to the user's requirements, compatibility checking can be performed in various ways from the 
viewpoint of execution order and information to be checked, e.g. first DDI number/sub-address and then 
bearer capability or vice versa. 

B.3.2 Network-to-IVIS compatibility checking 

When the network is providing a basic service at the called side, the MS shall check that the basic service(s) offered by 
the network in the Bearer Capability information element(s) match(es) the basic services that the MS is able to support. 
If a mismatch is detected, then the MS shall proceed as follows: 

if the SETUP message contained two bearer capability information elements for only one of which a mismatch is 
detected, the MS shall either: 

under the conditions specified in 3GPP TS 27.001 [36] (e.g. TS 61 and TS 62), accept the SETUP message 
with a CALL CONFIRMED message containing the, possibly negotiated, bearer capability information 
element for which no mismatch is detected, or 

reject the call using cause No. 88 "incompatible destination". 

otherwise the MS shall reject the offered call using a RELEASE COMPLETE message with cause No. 88 
"incompatible destination". 

NOTE: The backup bearer capability IE is not subject to compatibility checking. 

When interworking with existing networks, limitations in network or distant user signalling (e.g. in the case of an 
incoming call from a PSTN or a call from an analogue terminal) may restrict the information available to the called MS 
in the incoming SETUP message (e.g. missing Bearer Capability Information Element or missing High Layer 
Compatibility Information Element). For compatibility checking, and handling of such calls see 3GPP TS 27.001 [36]. 

B.3.3 User-to-User compatibility checking 

See 3GPP TS 27.001 [36]. 



B.4 High layer compatibility checking 

See 3GPP TS 27.001 [36]. 
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Annex C (normative): 

Low layer information coding principles 

C.1 Purpose 

This annex describes principles that shall be used when the calling MS specifies information during call setup regarding 
low layer capabilities required in the network and by the destination terminal. Refer also to 3GPP TS 27.001 [36]. 

NOTE: In this context and throughout this annex the term "called user" is the end point entity which is explicitly 
addressed. This may also be an explicitly addressed interworking unit (IWU) (see ITU-T I.500-Series 
Recommendations and ITU-T Recommendation X.31 case a). 



C.2 Principles 

C.2.1 Definition of types of information 

There are three different types of information that the calling PLMN user may specify during call setup to identify low 
layer capabilities needed in the network and in the destination terminal: 

a) type I information is information about the calling terminal which is only used at the destination end to allow a 
decision regarding terminal compatibility. An example would be the user information layer 3 protocol. Type I 
information is encoded in octets 5 to 7 of the low layer compatibility information element; 

b) type II information is only used by the network (PLMN) to which the calling user is connected for selection of 
PLMN specific network resources, e.g. channel type or specific functionality within the interworking function 
(IWF, see 3GPP TS 23.093 [88a]). This type of information is always present. An example is the connection 
element. Type II information is coded in: 

i) octet 3 of the bearer capability information element when the information transfer capability required by the 
calling user is speech ; 

ii) octets 3, 4, 5, and optionally octet 7 of the bearer capability information element when the information 
transfer capability required by the calling user is not speech; 

c) type III information is required for selection of a basic service from the choice of basic services offered by the 
network and together with type II information for selection of an appropriate interworking function (IWF, see 
3GPP TS 29.007 [38]), as well as for terminal compatibility checking at the destination terminal. An example is 
the information transfer capability. Type III information is always present and is encoded in: 

i) octet 3 of the bearer capability information element when the information transfer capability required by the 
calling user is speech ; 

ii) octets 3, 5, 6, 6a, 6b and 6c of the bearer capability information element when the information transfer 
capability required by the calling user is not speech; 



C.2.2 Examination by network 



Type I information is user-to-user (i.e. at the calling side not examined by network) while type II and III information 
should be available for examination by the destination user and the network. 

NOTE: In the case of a mobile terminated call, if the type II and type III information is not sufficient for the 
selection of an appropriate interworking function, the type I information will also examined by the 
network. 
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C.2.3 Location of type I information 

Type I information (i.e. terminal information only significant to the called user) shall, when used, be included in the low 
layer compatibility information element. 

C.2.4 Location of types II and III information 

Type II information is included in the bearer capability information element. Type III information is also included in the 
bearer capability information element. The network may use and modify type III information (e.g. to provide 
interworking). 

In any case a modification of the bearer capability information element has to be performed when interworking to the 
fixed network (e.g. ISDN) is required, where the signalling of the radio interface has to be mapped to fixed network 
signalling (e.g. mapping of GSM BCIE to ISDN BCIE, see 3GPP TS 29.007 [38]). 

C.2.5 Relationship between bearer capability and low layer 
compatibility information elements 

There shall be no contradiction of information between the low layer compatibility and the bearer capability at the 
originating side. However, as some bearer capability code points maybe modified during the transport of the call (e.g. 
by the interworking function), this principle implies that there should be minimal duplication of information between 
the bearer capability information element and the low layer compatibility information element. 

NOTE: If as a result of duplication, a contradiction occurs at the terminating side between the bearer capability 
information element and the low layer compatibility information element at the terminating side, the 
receiving entity shall ignore the conflicting information in the low layer compatibility information 
element. 
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Annex D (informative): 

Examples of bearer capability information element coding 

This annex gives examples of the coding of bearer capabiHty information elements for various telecommunication 
services. This annex is included for information purposes only. In the case of any inconsistency between this annex and 
3GPP TS 27.001 [36], then 3GPP TS 27.001 [36] shall take precedence over this annex. 

D.1 Coding for speech for a full rate support only mobile 
station 

D.1 .1 Mobile station to network direction 
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D.2 An example of a coding for modem access with V22- 
bis, 2,4 kbit/s, 8 bit no parity 

D.2.1 Mobile station to network direction, data compression 
allowed 
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D.2.2 Network to mobile station direction, data compression 
possible 
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D.3 An example of a coding for group 3 facsimile (9,6 
kbit/s, transparent) 

D.3.1 Mobile station to network direction 
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D.3.2 Network to mobile station direction 
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Annex E (informative): 

Comparison between call control procedures specified in 

3GPP TS 24.008 and ITU-T Recommendation Q.931 

This annex summarizes a comparison of the procedures for call control as specified in ITU-T Recommendation Q.931 
(blue book) and 3GPP TS 24.008. 

If no comment is given, it means that the procedures specified in ITU-T Recommendation Q.93 1 and 3GPP TS 24.008 
are similar. However, it should be noted that even in such cases the procedures may be described in slightly different 
ways in the two documents. 

Table E.1/3GPP TS 24.008: Circuit-switched call control procedures 



Procedure 


Q.931 


3GPP TS 24.008 


Call establishment at the 
originating interface 


5.1 


5.2.1 


- call request 


5.1.1 


5.2.1.1.1 

en-bloc sending only 


- B-channel selection originating 


5.1.2 


not applicable 


- overlap sending 


5.1.3 


not supported 


- invalid call information 


5.1.4 


5.2.1.1.2 


- call proceeding, en-bloc sending 


5.1.5.1 


5.2.1.1.3 


- call proceeding, overlap sending 


5.1.5.2 


not supported 


- notification of interworking at the 
originating interf. 


5.1.6 


5.2.1.1.4 


- call confirmation indication 


5.1.7 


5.2.1.1.5 


- call connected 


5.1.8 


5.2.1.1.6 


- call rejection 


5.1.9 


5.2.1.1.7 


- transit network selection 


5.1.10 


5.2.1.1.8 
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Table E.1/3GPP TS 24.008: Circuit-switched call control procedures (continued) 



Procedure 


Q.931 


3GPP TS 24.008 


Call establishment at the 
destination interface 


5.2 


5.2.2 


- call indication 


5.2.1 


5.2.2.1 

procedure for multiple terminal 
configuration not required, i.e. 
delivery of SETUP messages on 
broadcast data links is not supported 


- compatibility checking 


5.2.2 


5.2.2.2 

equivalent, except that delivery of 
SETUP messages on broadcast data 
links is not supported 


- B-channel selection destination 


5.2.3 


not applicable 


- overlap receiving 


5.2.4 


not supported 


- call confirmation information 


5.2.5 


5.2.2.3 

equivalent, except that delivery of 
SETUP messages on broadcast data 
links is not supported 


- notification of interworking at the 
terminating interf. 


5.2.6 


5.2.2.4 


- call accept indication 


5.2.7 


5.2.2.5 


- active indication 


5.2.8 


5.2.2.6 

equivalent, except that SETUP 
messages are not sent on broadcast 
data links 


- non-selected user clearing 


5.2.9 


not applicable 
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Table E.1/3GPP TS 24.008: Circuit-switched call control procedures (continued) 



Procedure 


Q.931 


3GPP TS 24.008 


Call clearing 

- terminology 

- exception conditions 

- clearing initiated by the user/MS 

- clearing initiated by the network 

- clearing when 
tones/announcements are 
provided 

- clearing when 
tones/announcements are not 
provided 

- completion of clearing 
Clear collision 


5.3 
5.3.1 

5.3.2 

5.3.3 
5.3.4 
5.3.4.1 

5.3.4.2 

5.3.4.3 
5.3.5 


5.4 

5.4.1 

terminology adapted to A/Gb mode 

and GERAN lu mode applications 

5.4.2 

only case a) of clause 5.3.2 of Rec. 
Q.931 applies. All other exceptions 
apply to functions which are not 
relevant to A/Gb mode and GERAN 
lu mode 

5.4.3 

5.4.4 

5.4.4.1.1 and 5.4.4.2.1 
exception: if not already connected, 
the traffic channel is connected in 
order to provide the 
tone/announcement 

5.4.4.1.2 and 5.4.4.2.3 

5.4.4.1.3 and 5.4.4.2.5 
5.4.5 
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Table E.1/3GPP TS 24.008: Circuit-switched call control procedures (continued) 



Procedure 


Q.931 


3GPP TS 24.008 


In-band tones and 


5.4 


5.5.1 


announcements 






Restart procedure 


5.5 


not supported 


Call rearrangements 


5.6 


5.3.4 

call suspension/call re-establishment 
not supported on the radio path. 
The functions, if required, are to be 
supported locally in the MS. On the 
radio interface, the notification 
procedure of Rec. Q.931 
(clause5.6.7) applies 


Call collisions 


5.7 


5.5.2 

call collisions cannot occur 


Emergency call establishment at 


not specified 


5.2.1.2 


the originating interface 


not supported 




In-call modification 


Annex 
Rec. Q.931 is 
incomplete with 
regard to in-call 
modification 
procedures 


5.3.4 


DTIVIF protocol control 


not specified 


5.3.3 


procedures 


not supported 




Call re-establishment 


not specified 
not supported 


5.5.4 


Status enquiry procedure 


5.8.10,5.8.11 


5.5.3 


User-to-user signalling 


7 


3GPPTS 24.010 [21] 


User notification procedure 


5.9 


5.3.1 
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Annex F (informative): 

A/Gb mode specific cause values for radio resource 

management 

See 3GPPTS 44.018 [84]. 
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Annex G (informative): 

3GPP specific cause values for mobility management 

This annex describes the cause values for the mobility management procedures for non-GPRS services (MM) and 
GPRS services (GMM). Clauses Gl to G5 are vaUd for both MM and GMM. However, the following codes are 
applicable for non-GPRS services only: 

#38 Call cannot be identified 

Clause G.6 applies only for GMM procedures. 

G.1 Causes related to MS identification 

Cause value = 2 IMSI unknown in HLR 

This cause is sent to the MS if the MS is not known (registered) in the HLR. This cause code does not affect 
operation of the GPRS service, although is may be used by a GMM procedure. 

Cause value = 3 Illegal MS 

This cause is sent to the MS when the network refuses service to the MS either because an identity of the MS is 
not acceptable to the network or because the MS does not pass the authentication check, i.e. the SRES received 
from the MS is different from that generated by the network. When used by an MM procedure, except the 
authentication procedure, this cause does not affect operation of the GPRS service. 

Cause value = 4 IMSI unknown in VLR 

This cause is sent to the MS when the given IMSI is not known at the VLR. 

Cause value = 5 IMEI not accepted 

This cause is sent to the MS if the network does not accept emergency call establishment using an IMEI or not 
accept attach procedure for emergency services using an IMEI. 

Cause value = 6 Illegal ME 

This cause is sent to the MS if the ME used is not acceptable to the network, e.g. blacklisted. When used by an 
MM procedure, this cause does not affect operation of the GPRS service. 

G.2 Cause related to subscription options 

Cause value =11 PLMN not allowed 

This cause is sent to the MS if it requests location updating in a PLMN where the MS, by subscription or due to 
operator determined barring is not allowed to operate. 

Cause value =12 Location Area not allowed 

This cause is sent to the MS if it requests location updating in a location area where the HPLMN determines that 
the MS, by subscription, is not allowed to operate. 

NOTE: If cause #12 is sent to a roaming subscriber the subscriber is denied service even if other PLMNs are 
available on which registration was possible. 

Cause value =13 Roaming not allowed in this location area 

This cause is sent to an MS which requests location updating in a location area of a PLMN which by 
subscription offers roaming to that MS but not in that Location Area. 
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Cause value = 15 No Suitable Cells In Location Area 

This cause is sent to the MS if it requests location updating in a location area where the MS, by subscription, is 
not allowed to operate, but when it should find another allowed location area in the same PLMN. 

NOTE: Cause #15 and cause #12 differ in the fact that cause #12 does not trigger the MS to search for another 
allowed location area on the same PLMN. 

Cause value = 25 Not authorized for this CSG 

This cause is sent to the MS if it requests access in a CSG cell where the MS either has no subscription to 
operate or the MS's subscription has expired and it should find another cell in the same PLMN. 

NOTE: The MS not supporting CSG will not receive cause# 25, as such a MS is not supposed to try to access a 
CSG cell. 



G.3 Causes related to PLMN specific network failures 
and congestion/Authentication Failures 

Cause value = 20 MAC failure 

This cause is sent to the network if the USIM detects that the MAC in the AUTHENTICATION REQUEST or 
AUTHENTICATION_AND_CIPHERING REQUEST message is not fresh (see 3GPP TS 33.102 [5a]). 

Cause value = 21 Synch failure 

This cause is sent to the network if the USIM detects that the SQN in the AUTHENTICATION REQUEST or 
AUTHENTICATION_AND_CIPHERING REQUEST message is out of range (see 3GPP TS 33.102 [5a]). 

Cause value =17 Network failure 

This cause is sent to the MS if the MSC cannot service an MS generated request because of PLMN failures, e.g. 
problems in MAP. 

Cause value = 22 Congestion 

This cause is sent if the service request or LOCATION UPDATING REQUEST message cannot be actioned 
because of congestion (e.g. congestion of the MSC or SGSN or GGSN or PDN Gateway; no channel; facility 
busy/congested etc.). 

Cause value = 23 GSM authentication unacceptable 

This cause is sent to the network in lu mode if a USIM is inserted in the MS and there is no Authentication 
Parameter AUTN IE present in the AUTHENTICATION REQUEST or 
AUTHENTICATION_AND_CIPHERING REQUEST message. 



G.4 Causes related to nature of request 

Cause value = 32 Service option not supported 

This cause is sent when the MS requests a service/facility in the CM SERVICE REQUEST message which is not 
supported by the PLMN. 

Cause value = 33 Requested service option not subscribed 

This cause is sent when the MS requests a service option for which it has no subscription. 

Cause value = 34 Service option temporarily out of order 

This cause is sent when the MSC cannot service the request because of temporary outage of one or more 
functions required for supporting the service. 
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Cause value = 38 Call cannot be identified 

This cause is sent when the network cannot identify the call associated with a call re-establishment request. 

G.5 Causes related to invalid messages 

Cause value = 95 Semantically incorrect message. 

See annex H, subclause H.5.10. 
Cause value = 96 Invalid mandatory information. 

See annex H, subclause H.6.1. 
Cause value = 97 Message type non-existent or not implemented. 

See annex H, subclause H.6.2. 
Cause value = 98 Message not compatible with protocol state. 

See annex H, subclause H.6.3. 
Cause value = 99 Information element non-existent or not implemented. 

See annex H, subclause H.6.4. 
Cause value =100 Conditional IE error. 

See annex H, subclause H.6.5. 
Cause value =101 Message not compatible with protocol state. 

See annex H, subclause H.6.6. 
Cause value =111 Protocol error, unspecified. 

See annex H, subclause H.6.8. 

G.6 Additional cause codes for GMM 

Cause value = 7 GPRS services not allowed 

This cause is sent to the MS when it is not allowed to operate GPRS services. 
Cause value = 8 GPRS services and non-GPRS services not allowed 

This cause is sent to the MS when it is not allowed to operate either GPRS or non-GPRS services. 

Cause value = 9 MS identity cannot be derived by the network 

This cause is sent to the MS when the network cannot derive the MS's identity from the P-TMSI in case of inter- 
SGSN routing area update. 

Cause value =10 Implicitly detached 

This cause is sent to the MS either if the network has implicitly detached the MS, e.g. some while after the 
Mobile reachable timer has expired, or if the GMM context data related to the subscription dose not exist in the 
SGSN e.g. because of a SGSN restart. 

Cause value = 14 GPRS services not allowed in this PLMN 

This cause is sent to the MS which requests GPRS service in a PLMN which does not offer roaming for GPRS 
services to that MS. 
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Cause value =16 MSC temporarily not reachable 

This cause is sent to the MS if it requests a combined GPRS attach or routing are updating in a PLMN where the 
MSC is temporarily not reachable via the GPRS part of the network. 

Cause value = 40 No PDP context activated 

This cause is sent to the MS if the MS requests an establishment of the radio access bearers for all active PDP 
contexts by sending a SERVICE REQUEST message indicating "data" to the network, but the SGSN does not 
have any active PDP context(s). 
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Annex H (informative): 

3GPP specific cause values for call control 

H.1 Normal class 

H.1.1 Cause No. 1 "unassigned (unallocated) number" 

This cause indicates that the destination requested by the mobile station cannot be reached because, ahhough the 
number is in a vaHd format, it is not currently assigned (allocated). 

H.1 .2 Cause No. 3 "no route to destination" 

This cause indicates that the called user cannot be reached because the network through which the call has been routed 
does not serve the destination desired. 

H.1 .3 Cause No. 6 "channel unacceptable" 

This cause indicates the channel most recently identified is not acceptable to the sending entity for use in this call. 

H.1 .4 Cause No. 8 "operator determined barring" 

This cause indicates that the MS has tried to access a service that the MS's network operator or service provider is not 
prepared to allow. 

H.1 .5 Cause No.1 6 "normal call clearing" 

This cause indicates that the call is being cleared because one of the users involved in the call has requested that the call 
be cleared. 

Under normal situations, the source of this cause is not the network. 

H.1. 6 Cause No.17 "user busy" 

This cause is used when the called user has indicated the inability to accept another call. 
It is noted that the user equipment is compatible with the call. 

H.1 .7 Cause No. 1 8 "no user responding" 

This cause is used when a user does not respond to a call establishment message with either an alerting or connect 
indication within the prescribed period of time allocated (defined by the expiry of either timer T303 or T3 10). 

H.1 .8 Cause No. 1 9 "user alerting, no answer" 

This cause is used when a user has provided an alerting indication but has not provided a connect indication within a 
prescribed period of time. 
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H.1 .9 Cause No. 21 "call rejected" 

This cause indicates that the equipment sending this cause does not wish to accept this call, although it could 
have accepted the call because the equipment sending this cause is neither busy nor incompatible. 

H.1.10 Cause No. 22 "number changed" 

This cause is returned to a calling mobile station when the called party number indicated by the calling mobile station is 
no longer assigned. The new called party number may optionally be included in the diagnostic field. If a network does 
not support this capability, cause No. 1 "unassigned (unallocated) number" shall be used. 

H.1 .1 Oa Cause No. 24 "call rejected due to feature at the 
destination" 

This cause is returned when the call is rejected due to a feature at the destination, e.g. Anonymous Call Rejection. This 
cause is only generated by the network. This cause is not generated by the MS. 

H.1 .1 1 Cause No. 25 "pre-emption" 

This cause is returned to the network when a mobile station clears an active call which is being pre-empted by another 
call with higher precedence. 

H.1 .12 Cause No. 26 "non-selected user clearing" 

Not supported. Treated as cause no. 31. 

H.1 .13 Cause No. 27 "destination out of order" 

This cause indicates that the destination indicated by the mobile station cannot be reached because the interface to the 
destination is not functioning correctly. The term "not functioning correctly" indicates that a signalling message was 
unable to be delivered to the remote user; e.g., a physical layer or data link layer failure at the remote user, user 
equipment off-line, etc. 

H.1 .1 4 Cause No. 28 "invalid number format (incomplete number)" 

This cause indicates that the called user cannot be reached because the called party number is not a valid format or is 
not complete. 

H.1 .15 Cause No. 29 "facility rejected" 

This cause is returned when a facility requested by user can not be provided by the network. 

H.1 .16 Cause No. 30 "response to STATUS ENQUIRY" 

This cause is included in STATUS messages if the message is sent in response to a STATUS ENQUIRY message. See 
also subclause 5.5.3. 

H.1. 17 Cause No. 31 "normal, unspecified" 

This cause is used to report a normal event only when no other cause in the normal class applies. 
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H.2 Resource unavailable class 

H.2.1 Cause No. 34 "no circuit/channel available" 

This cause indicates that there is no appropriate circuit/channel presently available to handle the call. 

H.2.2 Cause No. 38 "network out of order" 

This cause indicates that the network is not functioning correctly and that the condition is likely to last a relatively long 
period of time; e.g., immediately re-attempting the call is not likely to be successful. 

H.2.3 Cause No. 41 "temporary failure" 

This cause indicates that the network is not functioning correctly and that the condition is not likely to last a long period 
of time; e.g., the mobile station may wish to try another call attempt almost immediately. 

H.2.4 Cause No. 42 "switching equipment congestion" 

This cause indicates that the switching equipment generating this cause is experiencing a period of high traffic. 

H.2. 5 Cause No. 43 "access information discarded" 

This cause indicates that the network could not deliver access information to the remote user as requested; i.e., a user- 
to-user information, low layer compatibility, high layer compatibility, or sub-address as indicated in the diagnostic. 

It is noted that the particular type of access information discarded is optionally included in the diagnostic. 

H.2. 6 Cause No. 44 "requested circuit/channel not available" 

This cause is returned when the circuit or channel indicated by the requesting entity cannot be provided by the other 
side of the interface. 

H.2. 7 Cause No. 47 "resource unavailable, unspecified" 

This cause is used to report a resource unavailable event only when no other cause in the resource unavailable class 
applies. 



H.3 Service or option not available class 
H.3.1 Cause No. 49 -quality of service unavailable- 

This cause indicates to the mobile station that the requested quality of service, as defined in ITU-T Recommendation 
X.213, cannot be provided. 

H.3.2 Cause No. 50 -Requested facility not subscribed- 

This cause indicates that the requested supplementary service could not be provided by the network because the user 
has no completed the necessary administrative arrangements with its supporting networks. 
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H.3.3 Cause No. 55 -Incoming calls barred within the CUG- 

This cause indicates that although the called party is a member of the CUG for the incoming CUG call, incoming calls 
are not allowed within this CUG. 

H.3.4 Cause No. 57 -bearer capability not authorized- 

This cause indicates that the mobile station has requested a bearer capability which is implemented by the equipment 
which generated this cause but the mobile station is not authorized to use. 

H.3.5 Cause No. 58 -bearer capability not presently available- 

This cause indicates that the mobile station has requested a bearer capability which is implemented by the equipment 
which generated this cause but which is not available at this time. 

H.3.6 Cause No. 63 -service or option not available, unspecified- 

This cause is used to report a service or option not available event only when no other cause in the service or option not 
available class applies. 

H.3.7 Cause No. 68 -ACM equal to or greater than ACMmax- 

This cause is used by the mobile to indicate that call clearing is due to ACM being greater than or equal to ACMmax. 



H.4 Service or option not implemented class 
H.4.1 Cause No. 65 -bearer service not implemented- 

This cause indicates that the equipment sending this cause does not support the bearer capability requested. 

H.4.2 Cause No. 69 -Requested facility not implemented- 

This cause indicates that the equipment sending this cause does not support the requested supplementary service. 

H.4.3 Cause No. 70 -only restricted digital information bearer 
capability is available- 

This cause indicates that one equipment has requested an unrestricted bearer service, but that the equipment 
sending this cause only supports the restricted version of the requested bearer capability. 

H.4.4 Cause No. 79 -service or option not implemented, 
unspecified- 

This cause is used to report a service or option not implemented event only when no other cause in the service or 
option not implemented class applies. 
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H.5 Invalid message (e.g., parameter out of range) class 
H.5.1 Cause No. 81 -invalid transaction identifier value- 

This cause indicates that the equipment sending this cause has received a message with a transaction identifier 
which is not currently in use on the MS-network interface. 

H.5.2 Cause No. 87 -user not member of CUG- 

This cause indicates that the called user for the incoming CUG call is not a member of the specified CUG. 

H.5.3 Cause No. 88 -incompatible destination- 

This cause indicates that the equipment sending this cause has received a request to establish a call which has 
low layer compatibility, high layer compatibility, or other compatibility attributes (e.g., data rate) which cannot 
be accommodated. 

H.5.4 Cause No. 91 -invalid transit network selection- 

For further study. Treated as cause no. 95. 

H.5. 5 Cause No. 95 -semantically incorrect message- 

This cause is used to report receipt of a message with semantically incorrect contents (see subclause 8.8). 



H.6 Protocol error (e.g., unknown message) class 
H.6.1 Cause No. 96 -invalid mandatory information- 

This cause indicates that the equipment sending this cause has received a message with a non-semantical 
mandatory IE error (see subclause 8.5). 

H.6.2 Cause No. 97 -message type non-existent or not 
implemented- 

This cause indicates that the equipment sending this cause has received a message with a message type it does 
not recognize either because this is a message not defined, or defined but not implemented by the equipment 
sending this cause. 

H.6.3 Cause No. 98 -message type not compatible with protocol 
state- 

This cause indicates that the equipment sending this cause has received a message not compatible with the 
protocol state (subclause 8.4). 
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H.6.4 Cause No. 99 -information element non-existent or not 
implemented" 

This cause indicates that the equipment sending this cause has received a message which includes information 
elements not recognized because the information element identifier is not defined or it is defined but not 
implemented by the equipment sending the cause. However, the information element is not required to be 
present in the message in order for the equipment sending the cause to process the message. 

H.6.5 Cause No. 100 -conditional IE error- 

This cause indicates that the equipment sending this cause has received a message with conditional IE errors (see 
subclause 8.7.2). 

H.6.6 Cause No. 101 -message not compatible with protocol state- 

This cause indicates that a message has been received which is incompatible with the protocol state or that a 
STATUS message has been received indicating an incompatible call state. 

H.6.7 Cause No. 1 02 -recovery on timer expiry- 

This cause indicates that a procedure has been initiated by the expiry of a timer in association with 
3GPP TS 24.008 error handling procedures. 

H.6.8 Cause No. 1 1 1 -protocol error, unspecified- 

This cause is used to report a protocol error event only when no other cause in the protocol error class applies. 



H.7 Interworking class 

H.7.1 Cause No. 127 -interworking, unspecified- 

This cause indicates that there has been interworking with a network which does not provide causes for actions it 
takes; thus, the precise cause for a message which is being sent cannot be ascertained. 
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Annex I (informative): 

GPRS specific cause values for GPRS Session 

Management 

1.1 Causes related to nature of request 

Cause value = 8 Operator Determined Barring 

This cause code is used by the network to indicate that the requested service was rejected by the SGSN due to 
Operator Determined Barring. 

Cause value = 24 MBMS bearer capabilities insufficient for the service 

This cause code is used by the network to indicate that an MBMS context activation request was rejected by the 
network, because the MBMS bearer capabilities are insufficient for the MBMS service. 

Cause value = 25 LLC or SNDCP failure (A/Gb mode only) 

This cause code is used by the MS indicate that a PDP context is deactivated because of a LLC or SNDCP 
failure (e.g. if the SM receives a SNSM-STATUS. request message with cause "DM received " or " invalid XID 
response ", see 3GPP TS 44.065 [78]) 

Cause value = 26 Insufficient resources 

This cause code is used by the MS or by the network to indicate that a PDP context activation request, secondary 
PDP context activation request, PDP context modification request, or MBMS context activation request cannot 
be accepted due to insufficient resources. 

Cause value = 27 Unknown or missing access point name 

This cause code is used by the network to indicate that the requested service was rejected by the external packet 
data network because the access point name was not included although required or if the access point name 
could not be resolved. 

Cause value = 28 Unknown PDP address or PDP type 

This cause code is used by the network to indicate that the requested service was rejected by the external packet 
data network because the PDP address or type could not be recognised. 

Cause value = 29 User authentication failed 

This cause code is used by the network to indicate that the requested service was rejected by the external packet 
data network due to a failed user authentication. 

Cause value = 30 Activation rejected by GGSN, Serving GW or PDN GW 

This cause code is used by the network to indicate that the requested service was rejected by the GGSN, Serving 
GW or PDN GW. 

Cause value = 31 Activation rejected, unspecified 

This cause code is used by the network or by the MS to indicate that the requested service was rejected due to 
unspecified reasons. 

Cause value = 32 Service option not supported 

This cause code is used by the network when the MS requests a service which is not supported by the PLMN. 
Cause value = 33 Requested service option not subscribed 

See Annex G, clause 4. 
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Cause value = 34 Service option temporarily out of order 

See Annex G, clause 4. 

Cause value = 35 NSAPI already used 

This cause code may be used by a network to indicate that the NSAPI requested by the MS in the PDP context 
activation request is already used by another active PDP context of this MS. 

Never to be sent, but can be received from a R97/R98 network at PDP context activation 

Cause value = 36 Regular deactivation 

This cause code is used to indicate a regular MS or network initiated PDP context deactivation or a regular 
network initiated MBMS context deactivation. 

Cause value = 37 QoS not accepted 

This cause code is used by the MS if the new QoS cannot be accepted that were indicated by the network in the 
PDP Context Modification procedure. 

Cause value = 38 Network failure 

This cause code is used by the network to indicate that the PDP context deactivation or the MBMS context 
deactivation is caused by an error situation in the network. 

Cause value = 39 Reactivation requested 

This cause code is used by the network to request a PDP context reactivation (e.g. after a GGSN restart or after 
selection of a different GGSN by the network for Selected IP Traffic Offload). 

Cause value = 40 Feature not supported 

This cause code is used by the MS to indicate that the PDP context activation or the MBMS context activation 
initiated by the network is not supported by the MS. 

Cause value = 41 semantic error in the TFT operation. 

This cause code is used by the network or the MS to indicate that there is a semantic error in the TFT operation 
included in a secondary PDP context activation request or an MS -initiated PDP context modification or a 
network requested secondary PDP context activation. 

Cause value = 42 syntactical error in the TFT operation. 

This cause code is used by the network or the MS to indicate that there is a syntactical error in the TFT operation 
included in a secondary PDP context activation request or an MS -initiated PDP context modification or a 
network requested secondary PDP context activation. 

Cause value = 43 unknown PDP context 

This cause code is used by the network or the MS to indicate that the PDP context identified by the Linked TI IE 
in the secondary PDP context activation request or a network requested secondary PDP context activation is not 
active. 

Cause value = 44 semantic errors in packet filter(s) 

This cause code is used by the network or the MS to indicate that there is one or more semantic errors in packet 
filter(s) of the TFT included in a secondary PDP context activation request or an MS-initiated PDP context 
modification or a network requested secondary PDP context activation. 

Cause value = 45 syntactical error in packet filter(s) 

This cause code is used by the network or the MS to indicate that there is one or more syntactical errors in packet 
filter(s) of the TFT included in a secondary PDP context activation request or an MS-initiated PDP context 
modification or a network requested secondary PDP context activation. 

Cause value = 46 PDP context without TFT already activated 
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This cause code is used by the network or the MS to indicate that it has already activated a PDP context without 
TFT. 

Cause value = 47 Multicast group membership time-out 

This cause code is used by the network to indicate that the MBMS context is deactivated because the timer 
supervising the IGMP group membership interval (see RFC 3376 [107], subclause 8.4) or the MLD multicast 
listener interval (see RFC 2710 [108], subclause 7.4) expired. 

Cause value = 48 Request rejected. Bearer Control Mode violation 

This cause code is used by the network or the MS to indicate that the requested service was rejected because of 
Bearer Control Mode violation. 

Cause value = 50 PDP type IPv4 only allowed 

This cause is used by the network to indicate that the requested PDN connectivity is accepted with the restriction 
that only PDP type IPv4 is allowed. 

Cause value = 51 PDP type IPv6 only allowed 

This cause is used by the network to indicate that the requested PDN connectivity is accepted with the restriction 
that only PDP type IPv6 is allowed. 

Cause value = 52 single address bearers only allowed 

This cause is used by the network to indicate that the requested PDN connectivity is accepted with the restriction 
that only single IP version bearers are allowed. 

Cause value = 56 Collision with network initiated request. 

This cause code is used by the network to indicate that the MS-initiated request was rejected since the network 
has requested a secondary PDP context activation for the same service using a network-initiated procedure. 

Cause value = 60 Bearer handling not supported 

This cause code is used by the network to indicate that the procedure requested by the MS was rejected because 
the bearer handling is not supported. 

Cause value =112 APN restriction value incompatible with active PDP context. 

This cause code is used by the network to indicate that the PDP context(s) or MBMS context(s) have an APN 
restriction value that is not allowed in combination with a currently active PDP context. Restriction values are 
defined in 3GPP TS 23.060 [74], subclause 15.4. 



1.2 Causes related to invalid messages 

Cause value = 81 Invalid transaction identifier value. 

See annex H, subclause H.5.1. 
Cause value = 95 Semantically incorrect message. 

See annex H, subclause H.5.5. 
Cause value = 96 Invalid mandatory information. 

See annex H, subclause H.6.1. 
Cause value = 97 Message type non-existent or not implemented. 

See annex H, subclause H.6.2. 
Cause value = 98 Message not compatible with protocol state. 
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See annex H, subclause H.6.3. 
Cause value = 99 Information element non-existent or not implemented. 

See annex H, subclause H.6.4. 
Cause value =100 Conditional IE error. 

See annex H, subclause H.6.5. 
Cause value = 101 Message not compatible with protocol state. 

See annex H, subclause H.6.6. 
Cause value =111 Protocol error, unspecified. 

See annex H, subclause H.6.8. 
1.3 Void 
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Annex J (informative): 

Algorithm to encode frequency list information elements 

See 3GPPTS 44.018 [84]. 
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Annex K (informative): 

Default Codings of Information Elements 

The information in this annex does NOT define the value of any lEI for any particular message. This annex exists to aid 
the design of new messages, in particular with regard to backward compatibility with phase 1 mobile stations. 

K.1 Common information elements. 

For the common information elements types listed below, the default coding of information element identifier bits is 
summarized in table K.1/3GPP TS 24.008. 

Table K.1/3GPP TS 24.008: Default information element identifier coding 
for common information elements 



7 6 5 4 3 2 1 



1111 



10 1 

10 11 

10 111 

110 

11111 

10 



Type 1 info elements 

Notel 

Type 3 & 4 info elements 

Notel 

Location Area Identification 

IVIobile Identity 

Note 1 

Note 1 

Mobile Station classmark 3 



All other values are reserved 



Spare Half Octet 



Reference 
clause 



10.5.1.3 
10.5.1.4 



10.5.1.7 
10.5.1.8 



NOTE 1 : These values were allocated but never used in earlier phases of the protocol. 
NOTE 2: For GPRS common information elements no default values are defined: 

K.2 Radio Resource management information elements. 

See 3GPP TS 44.018 [84], annex K. 

K.3 Mobility management information elements. 

For the mobility management information elements listed below, the default coding of the information element 
identifier bits is summarized in table K.3/3GPP TS 24.008. 
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Table K.3/3GPP TS 24.008: Default information element identifier coding for mobility management 

information elements 



7 6 5 4 3 2 1 



10 1 
110 
1110 



10 10 



1 
10 



10 1 
10 10 
10 10 



Type 1 info elements 

Note 

Note 

Note 

Type 2 info elements 
Follow-on Proceed 
CTS Permission 

Type 3 & 4 info elements 

Note 

Note 

Note 



All other values are reserved 



Reference 
clause 



10.5.3.7 
10.5.3.10 



NOTE: These values were allocated but never used in earlier versions of the protocol 



K.4 Call control information elements. 

For the call control information elements listed below, the default coding of the information element identifiers is 
defined in table K.4/3GPP TS 24.008. 
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Table K.4/3GPP TS 24.008: Default information element identifier coding for call control information 

elements 









Reference 








clause 


8 7 6 5 4; 


J 2 1 






1 : : : - 


. . 


Type 1 info elements 




1- 




shift 


10.5.4.2 
and .3 


11- 


_ 


Note 




10 1- 


- - - 


Repeat indicator 


10.5.4.22 


10 10: 




Type 2 information elements 




( 


D 


IVIore data 


10.5.4.19 


( 


D 1 


CLIR Suppression 


10.5.4.11a 


( 


D 1 


CLIR Invocation 


10.5.4.11b 


( 


D 1 1 


Reverse call setup direction 


10.5.4.22a 


: : : : 




Type 3 & 4 info elements 
Bearer capability 










10.5.4.5 


1 ( 


D 


Cause 


10.5.4.11 


10 





Note 




10 


1 


Call Control Capabilities 


10.5.4.5a 


11 





Facility 


10.5.4.15 


11 


1 


Progress indicator 


10.5.4.21 


10 





Auxiliary states 


10.5.4.4 


10 


1 1 


Note 




10 1 





Keypad facility 


10.5.4.17 


110 





Signal 


10.5.4.23 


10 1 





Connected number 


10.5.4.13 


10 1 


1 


Connected subaddress 


10.5.4.14 


10 11 





Calling party BCD number 


10.5.4.9 


10 11 


1 


Calling party subaddress 


10.5.4.10 


10 11 


1 


Called party BCD number 


10.5.4.7 


110 1 


1 


Called party subaddress 


10.5.4.8 


1110 





Redirecting Party BCD 


10.5.4.21b 


1111 


1 


Redirecting Party subaddress 


10.5.4.21c 


1111 





Low layer compatib. 


10.5.4.18 


1111 


1 


High layer compatib. 


10.5.4.16 


1111 


1 


User-user 


10.5.4.25 


1111 


1 1 


SS version indicator 


10.5.4.24 



NOTE: These values were allocated but never used in earlier phases of the protocol. 
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Annex L (normative): 
Establishment cause (lu mode only) 

L.1 Mapping of NAS procedure to RRC establishment 
cause(lu mode only) 

When MM requests the estabHshment of a RR connection, the RRC estabhshment cause used by the MS shall be 
selected according to the CS NAS procedure as specified in table L.1.1. 

Table L.1.1/3GPP TS 24.008: Mapping of CS NAS procedure to establishment cause 



CS NAS procedure 


RRC Establishment cause (according 3GPP TS 25.331 [23c]) 


Originating CS speech call 


Originating Conversational Call 


Originating CS data call 


Originating Conversational Call 


CS Emergency call 


Emergency call 


Call re-establishment 


Call re-establishment 


Location update 


Registration 


IMSI Detach 


Detach 


MO SMS via CS domain 


Originating Low Priority Signalling 


Supplementary Services 


Originating High Priority Signalling 


Answer to circuit switched paging 


Set equal to the value of the paging cause used in the reception of paging in the 
RRC layer 


Answer to paging for CS fallback 


Terminating Conversational Call 


Terminating High Priority Signalling, if in the E-UTRAN, the RRC connection is 
released with cause CS Fallback High Priority. 


SS part of Location services 


Originating High Priority Signalling 


Any CS NAS procedure except CS 
Emergency call where the initiating 
uplink signalling message has 
Device properties indicating "MS is 
configured for NAS signalling low 
priority" 


Delay tolerant 



When GMM requests the establishment of a PS signalling connection, the RRC establishment cause used by the MS 
shall be selected according to the PS NAS procedure as specified in Table L. 1 .2. 
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Table L.1.2/3GPP TS 24.008: Mapping of PS NAS procedure to establishment cause 



PS NAS procedure 


RRC Establishment cause (according 3GPP TS 25.331 [23c]) 


GPRS Attach 


If the ATTACH REQUEST has Attach type not set to "Emergency attach", the RRC 
establishment cause shall be set to Registration except when the MS initiates 
attach procedure to establish emergency bearer services. 


If the ATTACH REQUEST has Attach type set to "Emergency attach" or if the 
ATTACH REQUEST has Attach type not set to "Emergency attach" but the MS 
initiates the attach procedure on receiving request from upper layer to establish 
emergency bearer services, the RRC establishment cause shall be set to 
Emergency call. (See Note 2) 


Routing Area Update - for the case 
of 'Directed Signalling Connection 
Re-Establishment (see chapter 
4.7.2.5.) 


If the MS does not have a PDN connection established for emergency bearer 
services, the RRC establishment cause shall be set to Call Re-Establishment. 


If the MS has a PDN connection established for emergency bearer services, the 
RRC establishment cause shall be set to Emergency call. (See Note 2) 


Routing area Update - all cases 
other than 'Directed Signalling 
Connection Re-Establishment 


If the MS does not have a PDN connection established for emergency bearer 
services, the RRC establishment cause shall be set to Registration. 


If the MS has a PDN connection established for emergency bearer services, the 
RRC establishment cause shall be set to Emergency call. (See Note 2) 


GPRS Detach 


Detach 


Request to re-establish RABs 


If the request is not to re-establish RABs for emergency bearer services, the RRC 
establishment cause shall be set to either 'Qriginating Conversational Call' or 
'Originating Streaming Call' or 'Originating Interactive Call' or 'Originating 
Background Call ' - depending on the Traffic Class in QoS of the "most 
demanding" RAB. (see Note 1) 


If the request is to re-establish RABs for emergency bearer services, the RRC 
establishment cause shall be set to Emergency call. (See Note 2) 


Request to establish a PS signalling 
connection for MBMS 


MBMS reception or MBMS p-t-p RB request 


Activate PDP Context 


If the ACTIVATE PDP CONTEXT REQUEST has the Request Type not set to 
"emergency", the RRC establishment cause shall be set to either 'Originating 
Conversational Call' or 'Originating Streaming Call' or 'Originating Interactive Call' 
or 'Originating Background Call ' - depending on the Traffic Class in OoS of the 
"most demanding" RAB. (see Note 1) - 

If Traffic Class in QoS is not 'Conversational Class' or 'Streaming Class' or 
'Interactive Class' or 'Background Class' but is 'Subscribed Traffic Class', then 
'Originating Subscribed traffic Call' shall be used. 


If the ACTIVATE PDP CONTEXT REQUEST has the Request Type set to 
"emergency", the RRC establishment cause shall be set to Emergency call. (See 
Note 2) 


IVIodify PDP Context 


Originating High Priority Signalling 


Deactivate PDP Context 


Originating High Priority Signalling 


MO SIVIS via PS domain 


Originating Low Priority Signalling 


SS part of Location services 


Originating High Priority Signalling 


Answer to packet paging 


If the MS does not have a PDN connection established for emergency bearer 
services, the RRC establishment cause shall be set equal to the value of the 
paging cause used in the reception of paging in the RRC layer. 


If the MS has a PDN connection established for emergency bearer services, the 
RRC establishment cause shall be set to Emergency call. (See Note 2) 


Any PS NAS procedure where the 
initiating uplink signalling message 
has Device properties indicating "IVIS 
is configured for NAS signalling low 
priority" except if Attach type is set to 
"Emergency attach" or Request type 
is set to "emergency" or MS has a 


Delay tolerant 
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PDN connection established for 
emergency bearer services 



NOTE 1 : For classification of "most demanding" Traffic Class the following ranking order applies: "Conversational" 

followed by "Streaming" followed by "Interactive" followed by "Background", where "Conversational" is the most 

demanding Traffic class in terms of being delay sensitive. 

In choosing the "most demanding" Traffic Class all already active PDP Context together with the PDF Context 

to be activated shall be considered 
NOTE 2: The emergency bearer services are only supported in UTRAN lu mode. 



NOTE: The RRC establishment cause may be used by the network to prioritise the connection establishment 
request from the MS at high load situations in the network. 
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Annex M (normative): 

Additional Requirements for backward compatibility with 

PCS 1900 for NA revision ME 

This annex provides additional requirements to support network mechanisms for backward compatibility with PCS 
1900 for NA revision mobile equipments (applicable until July 1, 1998). 

PCS 1900 for NA revision mobile equipments are defined to understand Mobile Network Codes made of up to 2 
digits. However federal regulation mandates that a 3-digit MNC shall be allocated by each administration to network 
operators. Therefore each network operator is identified by a 3-digit Mobile Country Code and a 3-digit Mobile 
Network Code. An operator whose network code complies to the allocation principle specified for PCS 1900 for NA 
and wants to achieve for a transition period of time the backward compatibility with PCS 1900 for NA revision 
mobile equipments shall apply the following: 

The network shall send over the air interface the 3-digit Mobile Country Code and only the two most significant 
digits of the Mobile Network Code (the value of the "digit" sent instead of the 3rd digit "" specified in 3GPP TS 
24.008, subclause 10.5.1.3) (see note). 

When a PCS 1900 for NA (revision greater than 0) mobile equipment recognizes over the air the Mobile Country Code 
and the two most significant digits of the Mobile Network Code as being the HPLMN codes of the current IMSI, the 
mobile equipment shall take into account the value of the sixth IMSI digit read from the SIM/USIM. If this value 
matches to a value contained in the limited set of values for the least significant MNC digit assigned by the number 
administration bodies for PCS 1900 for NA then the following applies for the mobile equipment: 

The value sent over the air instead of the 3rd MNC di'^'t in the Location Area Identification (for coding see 3GPP 
TS 24.008, subclause 10.5.1.3) shall be interpreted as the value of the sixth IMSI digit read from the SIM/USIM. 

NOTE: It is still a network operator option to apply this requirement after July 1, 1998. However, in this case the 
following shall be considered: 

1 . Network selection considerations for overlapping networks: 

Networks overlapping to the HPLMN, identified over the radio interface by an identical combination 
MCCl MCC2 MCC3 MNCl MNC2 (possible after July 1, 1998) may be selectable by PCS 1900 for 
NA mobile equipments revision with the same priority as the HPLMN or presented to the user as the 
HPLMN. 

2 Roaming considerations: 

- Roamers (SIM/USIM) from networks identified by an identical combination MCCl MCC2 MCC3 
MNCl MNC2 (possible after July 1, 1998) when roaming into the operator network with PCS 1900 
for NA mobile equipments revision 0, may cause these equipments to exhibit an unpredictable 
behaviour (e.g. looping in the HPLMN selection and registration procedures). 

Home subscribers (SIM/USIM) roaming with PCS 1900 for NA mobile equipments revision into 
networks identified by an identical combination MCCl MCC2 MCC3 MNCl MNC2 (possible after 
July 1, 1998), may consider being attached to the HPLMN. 
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Annex N (normative): 

Ranking of reject causes for Location Registration (MM and 

GMM) in a shared network 

This annex describes how the reject cause is determined: 

for a Network Sharing non-supporting MS in a shared network with multi-operator core network (MOCN) 
configuration; or 

for any MS in a multi-operator core network (MOCN) with common GERAN, 

when a location registration request from the MS is redirected among CN operators via the shared RAN (see 3GPP TS 
23.251 [109]) and is rejected by all core networks. In the following, the term 'location registration' is used for location 
area updating, GPRS attach, combined GPRS attach, routing area updating, and combined routing area updating. 

i) If the location registration request was accepted, or if the location registration request was rejected with a reject 
cause different from #1 1, #12, #13, #14, and #15: 

- in UTRAN lu mode, the MSC or SGSN shall not include a redirection indication in the RANAP DIRECT 
TRANSFER message transmitting the location registration accept message or location registration reject 
message to the RNC. According to 3GPP TS 25.413 [19c], the RNC will then forward the location 
registration accept message or the location registration reject message to the MS. 

- in A/Gb mode, the MSC shall use DTAP message and SGSN shall use BSSGP DL-UNIDATA message to 
carry the location registration accept message or location registration reject message to the BSC. According 
to 3GPP TS 48.008 [85] and 3GPP TS 48.018 [86], the BSC will then forward the location registration accept 
message or location registration reject message to the MS. 

ii) If the location registration request was rejected with one of the reject causes #1 1, #12, #13, #14, and #15: 

- in UTRAN lu mode, the MSC or SGSN shall include a redirection indication in the RANAP DIRECT 
TRANSFER message transmitting the location registration reject message to the RNC. According to 3GPP 
TS 25.413 [19c], the RNC will then initiate the redirection procedure towards the next CN operator and treat 
the response from the core network according to (i) and (ii). 

- in A/Gb mode, the MSC shall use BSSMAP Reroute Command message and SGSN shall use BSSGP DL- 
UNIDATA message to transmit the location registration reject message to the BSC with a redirection 
indication. According to 3GPP TS 48.008 [85] and 3GPP TS 48.018 [86], the BSC will then initiate the 
redirection procedure towards the next CN operator and treat the response from the core network according 
to (i), (ii) and (iii). 

iii) If the location registration request was rejected with one of the reject causes #11, #12, #13, #14, and #15 by all 
CN operators taking part in the network sharing, the RNC for UTRAN lu mode or the BSC for A/Gb mode shall 
determine the reject cause with the highest rank from the received reject causes and send a location registration 
reject message containing this reject cause to the MS. 

The ranking of the reject causes, from the lowest rank to the highest rank, is given by: 

#11<#12<#13<#14<#15. 

iv) If the location registration request was rejected with one of the reject causes #1 1, #12, #13, #14, and #15 by all 
CN operators taking part in the network sharing in a specific location area, but there is at least one additional CN 
operator taking part in the network sharing in another location area of the shared network defined by the same 
common PLMN identity, the RNC for UTRAN lu mode or the BSC for A/Gb mode shall send a location 
registration reject message with the reject cause #15 to the MS. 
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Annex O (normative): 

3GPP capability exchange protocol 



0.1 Scope 



This annex specifies the protocol data units used by the 3GPP capability exchange protocol and procedures for the 
handling of unknown, unforeseen, and erroneous protocol data by the receiving MS. 

The 3GPP capability exchange protocol provides services for the end-to-end exchange of capabilities between MSs. It is 
a separate protocol which uses the user-to-user signalling service 1 of the layer 3 call control protocol as a means of 
transport. 

Functional procedures which use the 3GPP capability exchange protocol in the context of CSI are specified in 
3GPPTS 24.279 [116]. 



0.2 User-user protocol contents 

The user-user protocol contents is included in the user-user information element described in subclause 10.5.4.25. 

The user-user protocol contents is structured like the non-imperative part of a standard L3 message (see 
3GPP TS 24.007 [20], subclause 11.2) and is composed of a variable number of information elements of type 1, 2, 3 
and 4. The different formats (TV, TLV) and the categories of information elements (type 1, 2, 3 and 4) are defined in 
3GPPTS 24.007 [20]. 

Within the user-user protocol contents the information elements may occur in an arbitrary order. 

All information elements shall be included only once. 



8 


7 


6 5 4 3 


2 


1 


Information element 1 


Information element 2 




Information element K 



octet 4* 


octet 5* 


octet k* 


octet k+r 


octet r 


octet l+r 


octet m* 


octet m+1* 



octet n* 

Figure 0.1/3GPP TS 24.008 User-user information when the user-user protocol indicator is set to 

"3GPP capability exchange protocol" 



0.3 Information element identifier 

The information element identifier and its use are defined in 3GPP TS 24.007 [20]. 

For the information elements defined in subclause 0.4, the coding of the information element identifier bits is defined 
in table 0.2/3GPP TS 24.008. 
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For a method to determine from the information element identifier whether an unknown information element is of type 
1 or 2 (i.e. it is an information element of one octet length) or type 4 (i.e. the next octet is the length indicator indicating 
the length of the remaining of the information element) see 3GPP TS 24.007 [20], subclause 11.2.4. 

Table 0.1/3GPP TS 24.008: Information element identifier coding for user-user protocol information 

elements 



8 7 6 5 4 3 2 1 



10 
110 



10 10 



Type 1 information elements: 
Radio environment capability 
IIVI Status 

Type 2 information elements: 
Unused 



10 1 
10 

All other values are unused 



Type 3 and 4 information elements: 
Personal ME identifier 
UE capability version 



Reference 
clause 



0.4.2 
0.4.4 



0.4.1 
0.4.3 



0.4 Information elements 



0.4.1 Personal ME identifier 

The purpose of the personal ME identifier is to discriminate between MEs used by the same user (see TS 24.279 [116], 
subclause 4.2). 

NOTE: As the personal ME identifier is generated randomly, it is not guaranteed that it uniquely identifies a 
specific ME used by the same user. 

The personal ME identifier has the form PMI-XXXX, where XXXX is a 4-digit hexadecimal number. Only the 
hexadecimal number XXXX is coded in the personal ME identifier information element. 

The personal ME identifier information element is coded as shown in figure 0.2/3GPP TS 24.008 and table 0.2/3GPP 
TS 24.008. 

The personal ME identifier is a type 3 information element with 3 octets length. 



8 7 6 5 


4 3 2 1 


Personal ME identifier IE! 


ME identifier digit 2 


ME identifier digit 1 


ME identifier digit 4 


ME identifier digit 3 



octet 1 



octet 2 



octet 3 



Figure 0.2/3GPP TS 24.008 Personal ME identifier 
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Table 0.2/3GPP TS 24.008: Personal ME identifier 



ME identifier digits (octets 2, 


3) 


Bits 1 to 4 


or 


bits 5 to 8 


respectively, contain the binary encoding of a hexadecimal ME 


identifier digit. Digit 1 is 


the leftmost digit in the 4-digit hexadecimal number XXXX. 


Bits 










ME identifier digit value 


4 3 


2 


1 


Or 






8 7 


6 


5 






























1 






1 





1 









2 





1 


1 






3 


1 












4 


1 





1 






5 


1 


1 









6 


1 


1 


1 






7 


1 












8 


1 





1 






g 


1 


1 









A 


1 


1 


1 






B 


1 1 












C 


1 1 





1 






D 


1 1 


1 









E 


1 1 


1 


1 






F 



0.4.2 Radio environment capability 



The purpose of the radio environment capability is to provide information about the current radio environment of the 
MS. 

The radio environment capability information element is coded as shown in figure 0.3/3GPP TS 24.008 and 
table 0.3/3GPP TS 24.008. 

The radio environment capability is a type 1 information element with 1 octet length. 



8 7 6 5 


4 


3 


2 


1 


Radio environment capability 
lEI 



spare 



spare 



Spare 


CS/ 
PS 



octet 1 
Figure 0.3/3GPP TS 24.008 Radio environment capability contents 

Table 0.3/3GPP TS 24.008: Radio environment capability contents 



CS and PS capability (octet 1, bit 1) 

The CS and PS capability indicates whether the MS is in a radio environment that 
supports simultaneous use of CS and PS services (see 3GPP TS 24.279 [116]). 

simultaneous use of CS and PS services not supported 

1 simultaneous use of CS and PS services supported 

Bits 2 to 4 of octet 1 are spare and shall be coded as zero. 



0.4.3 UE capability version 



The purpose of the UE capability version is to inform the receiving MS that the capability of the sending MS has 
changed since the last UE capability exchange (see 3GPP TS 24.279 [116]). 
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The UE capability version information element is coded as shown in figure 0.4/3GPP TS 24.008 and table 0.4/3GPP 
TS 24.008. 

The UE capability version has the form UCV-XX, where XX is a 2-digit hexadecimal number. Only the hexadecimal 
number XX is coded in the UE capability version information element. 

The UE capability version information element is coded as shown in figure 0.4/3GPP TS 24.008 and table 0.4/3GPP 
TS 24.008. 

The UE capability version is a type 3 information element with 2 octets length. 



8 7 6 5 


4 3 2 1 


UE capability version lEI 


UE capability version digit 2 


UE capability version digit 1 



Figure 0.4/3GPP TS 24.008: UE capability version 



octet 1 



octet 2 



Table 0.4/3GPP TS 24.008: UE capability version 



UE capability 


version 


digits(octet 2) 


Bits 1 to 4 and bits 5 to 8, 


respectively, contain the binary encoding of a 2-digit 


hexadecimal UE capability version. Digit 1 is the leftmost digit. 


Bits 










UE capability version digit value 


4 3 
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Or 
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0.4.4 IM Status 

The purpose of the IM Status is to provide information about the IMS capability and registration state of a specific 
public user identity and it MS . 

NOTE: The definition of what is a public user identity can be found in 3GPP TS 23.003 [10]. 

The IM Status information element is coded as shown in figure 0.5/3GPP TS 24.008 and table 0.5/3GPP TS 24.008. 

The IM Status is a type 1 information element with 1 octet length. 
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IM Status lEI 



Spare 



spare 


IM 
Status 



octet 1 



Figure 0.5/3GPP TS 24.008 IM Status contents 



Table 0.5/3GPP TS 24.008: IM Status contents 



IM Status (octet 1) 



Bits 

2 





1 

1 



MS is not IM subsystem capable 

MS is IM subsystem registered 

MS is IM subsystem capable and willing to register to IM subsystem (NOTE 1) 

MS is IM subsystem capable but will not register to IM subsystem (NOTE 2) 



Bits 3 to 4 of octet 1 are spare and shall be coded as zero. 

NOTE 1 : This value indicates that a terminal can be configured to allow IMS registration 

without user intervention when required, for example when prompted by receiving 
an IM Status of "MS is IM subsystem registered" or "MS is IM subsystem capable 
and willing to register to IM subsystem" during establishment of a CS call. 

NOTE 2: This value indicates that the terminal will not IMS register without user permission. 



0.5 Handling of unknown, unforeseen, and erroneous 
protocol data 

0.5.1 General 

The following subclauses specifies procedures for the handling of unknown, unforeseen, and erroneous protocol data by 
the receiving MS. These procedures are called "error handling procedures", but in addition to providing recovery 
mechanisms for error situations they define a compatibility mechanism for future extensions of the protocols. 

Subclauses 0.5.2 to 0.5.5 shall be applied in order of precedence. 

For the definition of semantical and syntactical errors see 3GPP TS 24.007 [20], subclause 1 1.4.2. 

Where the description of information elements in the present document contains bits defined to be "spare bits", these 
bits shall set to the indicated value (usually 0) by the sending side, and their value shall be ignored by the receiving side. 

0.5.2 Not supported lEs, unknown lEIs 

The MS shall ignore all information elements which are not supported and all information elements with unknown lEI. 



0.5.3 Repeated lEs 



If an information element, for which repetition is not specified in subclause 0.2, is repeated in the user-user protocol 
contents, only the contents of the information element appearing first shall be handled and all subsequent repetitions of 
the information element shall be ignored. When repetition of information elements is specified, only the contents of 
specified repeated information elements shall be handled. If the limit on repetition of information elements is exceeded, 
the contents of information elements appearing first up to the limit of repetitions shall be handled and all subsequent 
repetitions of the information element shall be ignored. 
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0.5.4 Syntactically incorrect lEs 

The MS shall treat all lEs that are syntactically incorrect as not present in the user-user protocol contents. 

0.5.5 Semantically incorrect lEs 

When an IE with semantically incorrect contents is received, the foreseen reactions specified for the respective 
procedure are performed (e.g. in the context of CSl see 3GPP TS 24.279 [116], clauses 5, 6). If however no such 
reactions are specified, the MS shall ignore the IE. 
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Annex P (normative): 

Mobility management for IIVIS voice termination 

P.1 Introduction 

The present annex specifies additional requirements for GMM and EMM in the MS for the support of terminating 
access domain selection for voice calls or voice sessions by the network. 

Support of these mobility management procedures can be configured in the MS. Whether the "Mobility Management 
for IMS Voice Termination" setting is stored in the IMS management object as defined in 3GPP TS 24.167 [134] or in 
the MS is an implementation option. If this setting is missing, then "Mobility Management for IMS Voice Termination" 
is disabled. 



P. 2 Activation of mobility management for IMS voice 
termination 

An MS activates mobility management for IMS voice termination when: 

1) the MS's availabiUty for voice calls in the IMS (see 3GPP TS 24.301 [120], subclause 3.1) changes from "not 
available" to "available"; 

2) the MS is configured with "Mobility Management for IMS Voice Termination" enabled as defined in 

3GPPTS 24.167 [134]; 

3) the IMS voice over PS session indicator received for lu mode has the value 

"IMS voice over PS session supported in lu mode, but not supported in A/Gb mode", or 
the IMS voice over PS session indicator received for SI mode has the value 
"IMS voice over PS session in SI mode supported"; and 

4) at least one of the two parameters voice domain preference for UTRAN and voice domain preference for 
E-UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only". 

The MS deactivates mobility management for IMS voice termination when the MS's availability for voice calls in the 
IMS (see 3GPPTS 24.301 [120], subclause 3.1) changes from "available" to "not available". 



P. 3 Inter-system change between A/Gb mode and 
lu mode 

An MS is required to perform routing area updating for IMS voice termination if: 

1) the upper layers have indicated that the MS is available for voice calls in the IMS (see 3GPP TS 24.301 [120], 
subclause 3.1); 

2) the MS is configured with "Mobility Management for IMS Voice Termination" enabled as defined in 
3GPPTS 24.167 [134]; 

3) the "IMS voice over PS session indicator" received for lu mode has the value "IMS voice over PS session 
supported in lu mode, but not supported in A/Gb mode"; and 

4) the voice domain preference for UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only". 
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P. 4 Inter-system change between A/Gb mode and 
S1 mode 

An MS is required to perform routing area updating for IMS voice termination at inter-system change from S 1 mode to 
A/Gb mode and tracking area updating for IMS voice termination at inter-system change from A/Gb mode to S 1 mode 
if: 

1) conditions 1 and 2 of annex P. 3 are fulfilled; 

2) the "IMS voice over PS session indicator" received for SI mode has the value "IMS voice over PS session in 
SI mode supported"; and 

3) the voice domain preference for E-UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only". 

P. 5 Inter-system change between lu mode and S1 mode 

An MS is required to perform routing area updating for IMS voice termination at inter-system change from S 1 mode to 
lu mode and tracking area updating for IMS voice termination at inter-system change from lu mode to S 1 mode if: 

1) conditions 1 and 2 of annex P. 3 are fulfilled; and 

2) any of the following conditions a, b and c is fulfilled: 

a) the IMS voice over PS session indicators received for lu mode and S 1 mode have the values 

"IMS voice over PS session supported in lu mode, but not supported in A/Gb mode" and 
"IMS voice over PS session in SI mode not supported", and 
the voice domain preference for UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only"; 

b) the IMS voice over PS session indicators received for lu mode and S 1 mode have the values 

"IMS voice over PS session in lu mode and A/G mode not supported" and 
"IMS voice over PS session in SI mode supported", and 
the voice domain preference for E-UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only"; or 

c) the IMS voice over PS session indicators received for lu mode and S 1 mode have the values 

"IMS voice over PS session supported in lu mode, but not supported in A/Gb mode" and 

"IMS voice over PS session in SI mode supported", and 

exactly one of the voice domain preferences for UTRAN and E-UTRAN as defined in 3GPP TS 24.167 [134] 
is "CS voice only". 
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Annex Q (informative): 
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Release 4 for 3GPP TS 24.008 v4.0.0 is based on 3GPP TS 24.008 version 3.5.0. 
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12-2000 


NP-10 


NP-000670 


319 




Correction of PDP context duplication handling 


4.0.0 


4.1.0 


12-2000 


NP-10 


NP-000670 


321 




DRX parameter range correction 


4.0.0 


4.1.0 


12-2000 


NP-10 


NP-000671 


323 




RR connection replaced with PS signalling connection 


4.0.0 


4.1.0 




Jan-01 








Correction of the version and date in the Header title /Paget 


4.1.0 


4.1.1 



Date 


TSG# 


TSG Doc. 


CR 


Rev 


Subject/Comment 


Old 


New 


03-2001 


NP 11 


NP-010123 


266 


2 


Addition of type 4 lEs for P-TMSI Signature and GPRS Timer 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010127 


281 


4 


Optional support of UIVITS AKA by a GSM only R99 IVIE 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010116 


324 


1 


Add new cause value on 'ODB for the Packet Ohented Services' 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010123 


328 


1 


Correction to IVIM timer handling 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010151 


334 


1 


Add UMTS 1 .28 Mcps TDD capability support to MS CMS 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010123 


336 




Clarification of the establishment confirm for the signalling 
connection 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010123 


338 




Clarification of the location update abnormal cases b) and c) on 
the MS side 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010205 


344 


4 


unsynchronised PDP contexts - MS less (2) 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010128 


345 


1 


Update of MS classmark 2 and MS Network Capability to support 
LCS 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010123 


348 




Correction of GPRS ciphering key sequence number lEI 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010123 


350 


1 


Collisions cases of core network initiated paging and MS initiated 
GMM specific procedures 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010125 


358 




Using RAU procedure for MS RAC IE update 


4.1.1. 


4.2.0 


03-2001 


NP 11 


NP-010129 


360 


1 


Connection re-establishment on forward handover without lur 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010147 


363 


2 


Roaming resthctions for GPRS service 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010205 


365 


3 


Correction related to Cause of no CLI 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010129 


367 


1 


Clarification of TFT request during secondary PDP context 
activation. 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010146 


377 




Correction of DTM Multislot Capabilities in MS Classmark 3 and 
MS Radio Classmark 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010147 


378 




Alignment of MS identity IE length in ATTACH ACCEPT and 
RAU ACCEPT Messages 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010207 


379 


1 


Mapping of upper layer event to establishment cause 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010207 


380 


1 


Resume at Intersystem change from GSM to UMTS 


4.1.1 


4.2.0 
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CR 
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New 


03-2001 


NP 11 


NP-010207 


381 


1 


Collision case of CN initiated paging and MS initiated MM 
specific procedures 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010151 


382 




Addition of 1 .28 Mcps UTRA TDD capability support to MS Radio 
Access Capability 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010154 


383 




Add cause value #8(0DB) to the PDP context deactivation 
initiated by the network 


4.1.0 


4.2.0 


03-2001 


NP 11 


NP-010155 


384 


1 


Re-transmission of AUTHENTICATION REQUEST and 
AUTHENTICATION & CIPHERING REOUEST messages 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010205 


385 


1 


MS behaviour for "RB Release followed by RB setup" 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-oioieo 


386 




Presence of PDP address IE in Activate PDP Context Accept 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-oioieo 


387 




Correction of Revision Level in MS Classmark and MS Network 
Capability 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-oioieo 


388 




Unsync MSmore Rel4 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-oioieo 


389 


1 


Correction of incorrect references 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010210 


391 


1 


Equiv handling of PLMN with different PLMN codes 


4.1.1 


4.2.0 


03-2001 


NP 11 


NP-010208 


392 




Removal of CODEC type octet in supported CODECS list 


4.1.1 


4.2.0 


06-2001 










Editorials. 

Page 371 was missing,- which is a part of the table 10.5.146 (MS 
Radio Access Capability IE). Editors note in 4.5.1 .3.1 is deleted, 
and in chapter 4.7.3.2.4 and 4.7.5.2.4 the cause value #8 was 
swopped back to its original place as it was in v4.1 .1 . 


4.2.0 


4.2.1 


06-2001 


NP 12 


NP-010275 


333 


2 


Length of User-user IE 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010355 


394 




Missing SM cause 40 in table 1 0.5.6.6 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010272 


396 


3 


Modification to MS's MM states to enable LCS signalling on RR 
layer 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010352 


400 




Stored list of equivalent PLMNs and error/abnormal cases 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010351 


403 


4 


CLASSMARK1 , 2 and 3 corrections. 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010355 


411 


2 


Clarification of Network Initiated GPRS Detach Procedure 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010275 


416 


2 


Partial Roaming - restriction by location area 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010275 


418 


2 


The priority in the CALL PROCEEDING message for eMLPP 
supporting network 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010271 


419 


1 


Clean up related to V.23, X.75, X.25 and X.32 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010275 


421 


1 


Handling of MM reject causes 2, 3 and 6 by mobile stations 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010273 


422 




Extended uplink TBF 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-0102e7 


423 


1 


Correct coding errors in the MS Radio Access Capability IE 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010343 


428 


1 


Alignment of 24.008 authentication procedures with 33.102 


4.2.1 


4.3.0 


06-2001 


NP 12 


NP-010268 


426 


1 


Introduction of GTT (CTM) support 


4.3.0 


5.0.0 


09-2001 


NP-13 


NP-0 10493 


444 


1 


Old RAI handling 


5.0.0 


5.1.0 


09-2001 


NP-13 


NP-010499 


452 


1 


Modification of session management between MS and network 


5.0.0 


5.1.0 


09-2001 


NP-13 


NP-010533 


475 


2 


Introduction of default codec UMTS AMR 2 


5.0.0 


5.1.0 


09-2001 


NP-13 


NP-0 10493 


457 




Correction of Protocol configuration options 


5.0.0 


5.1.0 


09-2001 


NP-13 


NP-010490 


465 




Clarification of 8-PSK power class coding 


5.0.0 


5.1.0 


09-2001 


NP-13 


NP-010498 


468 


2 


Definition of new DTM multislot classes 


5.0.0 


5.1.0 


09-2001 


NP-13 


NP-010496 


474 




Remove references to specific sections of 25.331 


5.0.0 


5.1.0 


12-2001 


NP-14 


NP-0106eO 


458 


3 


Introduction of Source Statistics Descriptor 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010648 


479 


1 


Correction of the criteria for the usage of combined RAU 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010654 


481 




Correction of default codec selection criterion 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010678 


487 


1 


Mapping of NAS procedures to RRC Establishment Causes 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-0106eO 


488 




Correction of missing actions on RAND and T3218, T3316 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010658 


489 


2 


LCS capability for GPRS 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010659 


493 


2 


Usage of TMSI in Intra Domain Connection of RAN Nodes to 
Multiple CN Nodes 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010655 


495 


2 


RRC Establishment Causes for LCS Procedures 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010647 


498 




P-TMSI Signature handling 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010652 


501 




Correction of maximum transfer delay value in Qos IE 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010647 


507 




Handling of new/old TLLI in the network 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-0106eO 


510 


2 


Clarification on the EDGE parameters in the Mobile Station 
Classmark 3 IE 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010657 


516 


2 


Use of Supported Codec List (SCL) IE for all codec types 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010700 


527 


4 


Impact of regional roaming restrictions on the GMM context 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010678 


528 


2 


Conditions for the deletion of the equivalent PLMN list 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010665 


532 




Correction of references in 24.008 


5.1.0 


5.2.0 


12-2001 


NP-14 


NP-010690 


534 


1 


Introduction of GERAN feature indicator 


5.1.0 


5.2.0 


03-2002 










Editorial clean-up by ETSI/MCC. 


5.2.0 




03-2002 


NP-15 


NP-020042 


520 


2 


P-TMSI allocation in Attach procedure 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020042 


537 


1 


Mobile terminated call with single numbering scheme 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020039 


546 




Missing 3rd MNC definition 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020042 


550 


1 


Applicability of CM3 IE Modulation Capability information 


5.2.0 


5.3.0 
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CR 
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New 


03-2002 


NP-15 


NP-020043 


556 


3 


Upgrading PCO for supporting IIVIS services 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020044 


557 


2 


Upgrading TFT for supporting IIVIS services 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020038 


564 


1 


Handlling for QoS profile parameter "transfer delay" 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020038 


571 


1 


Conditions for including R97 QoS attributes in the QoS IE 


5.2.0 


5.3.0 


03-2002 


NP-15 


NP-020133 


575 




Deletion of reference to 23.071 in 24.008 


5.2.0 


5.3.0 


06-2002 


NP-ie 


NP-020220 


536 


2 


Correction of codec negotiation procedure 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020241 


551 


3 


Service cfiange and fallback for UDI/RDI multimedia calls 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


554 


2 


Restriction of thie Okbits maximum bitrate 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020223 


578 


2 


Authientication not accepted by MS 


5.3.0 


5.4.0 


06-2002 


NP-16 


NP-020219 


581 


1 


Correction to CS domain specific system information 


5.3.0 


5.4.0 


06-2002 


NP-16 


NP-020219 


592 


2 


Impact of regional roaming restrictions on tfie MM state 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020223 


595 




Correction of repeat indicator IE 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020223 


598 




Removal of thie coding rules of type 4 lEs 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020221 


601 


1 


Correction to text on DTMF handling 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


607 


1 


Handling of SM STATUS(#81 , #97) and invalid Tl of Secondary 
PDP context 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020219 


612 




R97 and R99 compatibility 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


615 




Deletion of ePLMN list when the fifth RAU attempt is reached 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


618 


1 


Conditions when to update the "RPLMN Last used Access 
Technology" information 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


619 


1 


SIM removal and change of RA during detach procedure 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020216 


625 


1 


Conflicting behaviour when UE receives 
AUTHENTICATION REJECT 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


626 




Correction of definition of SSD in QoS IE 


5.3.0 


5.4.0 


06-2002 


NP-16 


NP-020225 


630 




Support for IMS media Multiplexing in Session Management - 
Ihl 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


631 




Addition of missing references to TS 25.304 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020242 


632 


1 


DRX parameter update with RAU procedure 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020225 


634 


1 


PCO in Session Management procedures 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020217 


639 


1 


Alternative coding of radio access capabilities 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-020300 


641 


1 


Indication of support of LCS via the PS domain in lu-mode 


5.3.0 


5.4.0 


06-2002 


NP-ie 


NP-02031 1 


642 


2 


Addition of missing code point for 8-PSK Half Rate AMR 


5.3.0 


5.4.0 


09-2002 


NP-17 


NP-020382 


561 


3 


MM behaviour in case of a combined attach reject for the PS 
service 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020384 


643 


2 


GERAN lu Mode Capability 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020380 


644 




Go related error code to UE 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-0203e9 


650 




Removal of CB02 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020381 


651 


1 


Usage of the Service Request procedure 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020394 


652 


1 


MS behavior in case of change of network mode of operation 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020382 


653 


1 


MS behavior in case of T331 2 expiry 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020382 


654 


1 


Ambiguous MM behavior in case of a failed combined Attach or 
RAU 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-0203e8 


667 




Usage of Service Request type 'data' 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020371 


668 




Introduction of PCO in more session management messages 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020372 


669 




Request for DNS IPv6 server address 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020371 


670 




Clean-up of text for the PCO-IE 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-0203e8 


673 


3 


Correction to service request procedure 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020371 


675 




Indication of successful establishment of Dedicated Signalling 
PDP context to the UE 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-0203e8 


678 




Routing Area Update at network change 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020371 


679 




Coding of Authorisation Token in Traffic Flow Template 


5.4.0 


5.5.0 


09-2002 


NP-17 


NP-020382 


687 




Precedence of different RAU 


5.4.0 


5.5.0 


12-2002 


NP-18 


NP-020546 


697 




No MT calls after resumption of GPRS in Network Operation 
Model 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020570 


698 




Inclusion of EDGE RF Power Capability in the CM3 IE 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020670 


701 


3 


Flow Identifier Encoding 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020548 


703 




Clarification of the codec change procedure 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020629 


704 




Use of "LLC SAPI not assigned" by the network 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020545 


707 




Cell barring after Network authentication rejection from the UE 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020674 


716 


4 


Downloading of local emergency numbers to the mobile station 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020549 


721 




Correcting errors and making improvements to references 


5.5.0 


5.6.0 


12-2002 


NP-18 


NP-020547 


724 




Clarification on revision level 


5.5.0 


5.6.0 


03-2003 


NP-19 


NP-030042 


730 




Correction on CC Capabilities IE length 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030055 


731 




Support of UMTS authentication by GERAN only terminals 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030141 


736 


2 


MS RAC for UMTS only terminal 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030055 


737 




High multislot classes for type 1 mobiles 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030054 


738 


2 


Signalling PDP Context Indication to Core Network 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030055 


740 




Missing lEI definition in locking shift (CC) IE and non-locking shift 
(CC) IE 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030055 


741 




Combined RAU successful for GPRS only, missing GMM cause 
IE 


5.6.0 


5.7.0 
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Old 
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03-2003 


NP-19 


NP-030055 


746 




Enhanced Power Control (EPC) information in classmarl< 3 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-0300e2 


747 




Introduction of USIM in tfie figure "Overview mobility 
management protocol" 


5.6.0 


5.7.0 


03-2003 


NP-19 


NP-030057 


733 


1 


Interruption of DL user data transmission during P-TMSI 
reallocation 


5.7.0 


6.0.0 


03-2003 


NP-19 


NP-030058 


739 


2 


Implementation of new frequency ranges into 24.008 


5.7.0 


6.0.0 


06-2003 


NP-20 


NP-030284 


750 




MS RAC encoding 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-0302e9 


756 


3 


Bearer Capability IE 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030273 


760 




Alignment of parameter 'signalling information' with other QoS 
parameters 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030273 


764 


1 


Cleanup and correction of the PCO-IE 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030271 


767 


1 


Indication of the MS support of "Modulation based multislot 
class" 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030284 


768 




Wrong references in SETUP and redirected number/subaddress 
lEs 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030270 


772 




Alignment on BC IE coding for FAX between TS24.008 and 
TS27.001 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030267 


776 




Unciphered transmission of Authentication and Ciphering Failure 
in A/Gb mode 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030282 


780 




Correction of the static conditions for the bearer capability IE 
contents 


6.0.0 


6.1.0 


06-2003 


NP-20 


NP-030270 


784 


1 


Clarification of the procedure for the change of DRX parameter 


6.0.0 


6.1.0 


09-2003 










ETSI/MCC changed chapter numbering from 10.5.4.5.1 to 
10.5.4.4a.1 for Backup BC IE. Wrong since vO.O.O 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030416 


787 




Correction of the static conditions for the 'backup' bearer 
capability IE contents 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030416 


793 




Deletion of EFRPLMNAcT 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030416 


795 


1 


Clarification of handover- BC-IE 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030347 


797 


2 


Support of the maximum bit rate for HSDPA 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030420 


798 




Source of the CS domain specific system information 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030420 


799 


1 


Signaling connection release after GMM procedure 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030406 


807 


2 


Clarification of BC negotiation for multimedia calls 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030405 


813 


1 


Change of DTM core capability 


6.1.0 


6.2.0 


09-2003 


NP-21 


NP-030416 


815 


1 


CR on introduction of mobile station multislot power classes. 


6.1.0 


6.2.0 


1 2-2003 


NP-22 


NP-030485 


803 


2 


TFT error handling 


6.2.0 


6.3.0 


1 2-2003 


NP-22 


NP-030485 


816 




ePLMN list extension 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030485 


818 


1 


SM signalling in case tear down is requested 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030487 


819 




Addition of multiple TBF capability flag to MS RAC IE 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030485 


820 




Order of frequency bands in MS Radio Access Capability IE 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030481 


822 




Correction to the Multislot Power Profile Classes 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030485 


823 




Correction of timer handling in diagram 4.7.7a 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030485 


826 




Removal of codepoint for GTP ack mode 


6.2.0 


6.3.0 


12-2003 


NP-22 


NP-030485 


827 




SSD and Signalling indication in QoS IE 


6.2.0 


6.3.0 


03-2004 


NP-23 


NP-040038 


831 


2 


Use of TMSI/IMSI in CM SERVICE REOUEST message in case 
of emergency call redirection and change of LAI 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


832 




Clarification on the meaning of MS network capability indicator 
bits 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040025 


836 


1 


Conditions for PFI usage 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


841 


2 


Added Session Management (SM) Cause Value for APN Type 
Conflict 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


842 




Correction of the condition for the tear down of PDP contexts 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


844 




Status of PFI value after PDP context modification 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


845 


1 


MS reaction upon RRC connection release with cause "Directed 
signalling connection re-establishment" 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040099 


846 


3 


Handling of key sets 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


849 


2 


Clarification of UE behaviour at network initiated GPRS Detach 


6.3.0 


6.4.0 


03-2004 


NP-23 


NP-040038 


851 




MS class behaviour in case of a network inititated detach with 
detach type "IMSI detach" 


6.3.0 


6.4.0 


06-2004 


NP-24 


NP-040185 


856 


1 


Clarification of the use of service type 'Location services' 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040186 


860 


1 


Correction of the network initiated in-call modification 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040187 


863 


1 


Suspension of CM layer services during GMM procedures 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040187 


866 


1 


LCS VA capability in MS network capability IE for PS 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040203 


869 


1 


Introduction of Flexible Layer One lu capability 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040203 


871 


2 


Identity request for identity that is not available 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040186 


879 


2 


Reference to 4.7.X.4 


6.4.0 


6.5.0 


06-2004 


NP-24 


NP-040190 


881 


1 


Handling of key sets at inter-system change 


6.4.0 


6.5.0 


09-2004 


NP-25 


NP-040432 


882 


4 


Follow-on proceed for the PS domain 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040375 


901 


3 


Clarification on the registered PLMN for UEs that support 
network sharing in a shared network 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040376 


905 




Introduction of Downlink Advanced Receiver Performance 
(DARP) capability 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


889 


1 


Introduction of the MBMS general procedure and states 


6.5.0 


6.6.0 
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09-2004 


NP-25 


NP-040377 


890 


1 


Introduction of the MBMS Context Activation procedure 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


891 


1 


Introduction of the MBMS Context Activation messages 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


896 




Update of the Service Request procedure - MBMS 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


894 




Introduction of the MBMS Multicast Service Deactivation 
procedure - Reuse of PDP context deactivation messages 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


895 


1 


Introduction of the MBMS Multicast Service Deactivation 
messages - Reuse of PDP context deactivation messages 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


898 


1 


Introduction of MBMS context handling 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040377 


897 


1 


Update of Annex 1 for MBMS 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040378 


904 




Introduction of Extended RLC/MAC Control Message 
segmentation capability 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040378 


883 


1 


Mapping of QoS Traffic Class to RRC Establishment Cause 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040378 


852 


3 


Network Search for recovering from Faulty Networks 


6.5.0 


6.6.0 


09-2004 


NP-25 


NP-040379 


886 


2 


Correction to list of received N-PDU number in Rau Accept 
message 


6.5.0 


6.6.0 


12-2004 


NP-26 


NP-040504 


907 




MBMS update 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040504 


908 


2 


NSAPI at MBMS context activation 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040510 


922 




Addition of DTM enhancements capability 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040513 


926 


2 


Location registration in a shared network when multiple PLMNs 
are broadcast 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040513 


927 


1 


Reject cause ranking during rerouting in MOCN 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


910 


2 


Correction of terminology -GSM and UMTS 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


911 


1 


Paging for GPRS Services in GSM 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


912 


1 


Service request conditions 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


913 


1 


Service request - Abnormal cases in the MS 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


914 


2 


No follow on proceed indication 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


915 


3 


Mobile identity - No identity 


6.6.0 


6.7.0 


1 2-2004 


NP-26 


NP-040514 


920 


1 


Correction of the description of causes #7 and #8 in Annex G.6 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


921 


1 


CC cause reference correction 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


923 




Handling of zero T331 2 timer value 


6.6.0 


6.7.0 


12-2004 


NP-26 


NP-040514 


924 




Introduction of new references for DTMF 


6.6.0 


6.7.0 


03-2005 


NP-27 


NP-050070 


933 


2 


Defining TMGI and MBMS Session Id in the mobile identity field 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050070 


934 


1 


Correct GPRS SM List and MBMS IE Descriptions 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050070 


958 




Mapping of 'MBMS notification response' to RRC establishment 
cause 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050071 


931 




Synchronization of MBMS context status between UE and SGSN 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050071 


954 




MBMS Session Management clarifications 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050071 


956 




Introduction of MBMS in clause 8 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050076 


952 




Detach for PS and CS during a ongoing CS connection 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050076 


951 




GPRS attach type while in DTM 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050076 


953 




Condition for Combined RAU after a DTM connection 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050076 


935 




Missing Messages in MM and CC Summary Tables 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050076 


932 




Correction of the heading of subclause 4.7.3.1 .6, bullet d.1 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050077 


957 


2 


Modification of MS Behaviour under GPRS Attach with Reject 
Cause #14 


6.7.0 


6.8.0 
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03-2005 


NP-27 


NP-050083 


939 


3 


Addition of domain specific access control 


6.7.0 


6.8.0 


03-2005 


NP-27 


NP-050085 


950 


2 


Provision of IVIS specific UTRAN capabilities for the PS handover 
from GERAN to UTRAN 


6.7.0 


6.8.0 


06-2005 


CP-28 


CP-050058 


987 




GSIVI 750 corrections 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e2 


977 


1 


Introduction of MBMS support indication to the UE 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050067 


982 




Correction on handling of forbidden lists 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050069 


974 


1 


Cell Update triggered by low layers 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e9 


989 




Extension of DTM to high multislot classes 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e9 


975 




MS initiated RAU for re-negotiation of MS configuration 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e9 


973 


1 


Handling of duplicated RAU on the network side 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e9 


978 


2 


Clarification on locking shift procedure 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e9 


984 


1 


Mobile identity IE length when 'No identity' 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-0500e9 


916 


4 


Attach type and Update type lEs 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050069 


972 


1 


Corrections of designations and references of figures and 
tables 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050071 


990 


1 


SCUDIF: Introduction of a Network-initiated Service Upgrade 
capability 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050071 


991 


1 


SCUDIF: Introduction of a Network-initiated Service Upgrade 
indicator 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050071 


983 


1 


SCUDIF: Introduction of a new timer for service change 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050072 


937 


3 


SETUP Message Enhancement for Voice Video Switching 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050231 


962 


5 


Transparent data call request in dual mode case 


6.8.0 


6.9.0 


06-2005 


CP-28 


CP-050058 


988 




Introduction of GSM 710 


6.9.0 


7.0.0 


09-2005 


CP-29 


CP-050355 


1012 


2 


Clarification in TFT for the 'parameters list' 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-050356 


1003 


1 


Mapping RRC's "MBMS p-t-p RB Request" to a NAS service 
type 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-050356 


995 


1 


MBMS context procedures cleanup 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-050356 


997 




T3390 is not used for MBMS 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503ei 


1014 


1 


Support of encryption algorithms in mobile stations 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503ei 


1016 




Correction of terminology 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503e6 


1001 


1 


Correction of the definition of cause #13 "Roaming not allowed in 
this location area" 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503e6 


1004 




Editorial alignment of SM Cause values 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503e6 


1009 


2 


Clarification to Quality of Service Information Element 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503e6 


1022 


1 


Clarification of requirement on the emergency category 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503e6 


963 


3 


Guard timer for PS signaling connection release 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-0503e6 


999 


1 


Alignement of GMM T331 7 timer value 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-050370 


1023 


1 


Introduction of T-GSM 810 


7.0.0 


7.1.0 


09-2005 


CP-29 


CP-050449 


1006 


2 


Modifications for PS HO in A/Gb mode 


7.0.0 


7.1.0 


1 2-2005 


CP-30 


CP-050535 


1032 


1 


Description of 8-PSK capability on the uplink in MS Classmark 3 


7.1.0 


7.2.0 
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12-2005 


CP-30 


CP-050536 


1039 




Emergency number length in Emergency Number List IE 


7.1.0 


7.2.0 


12-2005 


CP-30 


CP-050536 


1035 




Correction of wrong codepoint in the user-user information IE 


7.1.0 


7.2.0 


12-2005 


CP-30 


CP-050540 


1025 




MBMS INACTIVE state does not exist 


7.1.0 


7.2.0 


12-2005 


CP-30 


CP-050545 


1041 


1 


Correction of Mobile Identity used in PAGING RESPONSE 
message 


7.1.0 


7.2.0 


12-2005 


CP-30 


CP-050553 


1027 


3 


Rationalised guard timer for Service Request (Service Type = 
Data) 


7.1.0 


7.2.0 


03-2006 


CP-31 


CP-060126 


1044 


1 


Use on cause #12 in VPLMNs 


7.2.0 


7.3.0 


03-2006 


CP-31 


CP-060114 


1050 


4 


Correction of domain specific access control 


7.2.0 


7.3.0 


03-2006 


CP-31 


CP-060115 


1052 


- 


Missing subclause in TS 24.008 


7.2.0 


7.3.0 


03-2006 


CP-31 


CP-060179 


1054 


2 


Inclusion of support for DTM Handover for GERAN A/Gb mode 


7.2.0 


7.3.0 


03-2006 


CP-31 


CP-060126 


1056 


1 


Clarification for collision of PDP context activation 


7.2.0 


7.3.0 


03-2006 


CP-31 


CP-060121 


1062 


1 


Transfer of Text from the Combinational Services TR 24.879 to 
TS 24.008 


7.2.0 


7.3.0 


03-2006 


CP-31 


CP-060113 


1064 


- 


Inclusion of support for Repeated SACCH 


7.2.0 


7.3.0 


06-2006 


CP-32 


CP-0602e2 


1067 




Incorrect reference to RFC 3513 


7.3.0 


7.4.0 


06-2006 


CP-32 


CP-060267 


1081 


1 


Indication of support for Repeated ACCH 


7.3.0 


7.4.0 


06-2006 


CP-32 


CP-060353 


1071 


2 


Removal of references to "MBMS notification response" service 
type 


7.3.0 


7.4.0 


09-2006 


CP-33 


CP-060454 


1103 


2 


Mitigating the risk of DoS attacks that utilises non-integrity 
protected NAS messages 


7.4.0 


7.5.0 


09-2006 


CP-33 


CP-060455 


1098 


1 


Enhanced NSAPI for MBMS Broadcast Mode 


7.4.0 


7.5.0 


09-2006 


CP-33 


CP-060459 


1089 


2 


Clarification on the handling of T331 1 and T3302 timers during 
DSAC 


7.4.0 


7.5.0 


09-2006 


CP-33 


CP-060459 


1085 


1 


Procedure at UE after unbarred for both domains on DSAC in 
NMOI 


7.4.0 


7.5.0 


09-2006 


CP-33 


CP-060459 


1083 


1 


Postponed RAU if T3312 expires while PS domain is barred 


7.4.0 


7.5.0 


09-2006 


CP-33 


CP-060473 


1104 


4 


Coding of the User-User Information Element for IMS status 


7.4.0 


7.5.0 


09-2006 


CP-33 


CP-060506 


1099 


1 


Implementation option to improve the performance of MM/GMM 
signaling procedures 


7.4.0 


7.5.0 


11-2006 


CP-34 


CP-060658 


1115 


1 


Correction of the GPRS MS action in NMO 1 when PS is barred 


7.5.0 


7.6.0 


11-2006 


CP-34 


CP-060658 


1111 


2 


Clarification on the detach procedure during domain specific 
access class barring 


7.5.0 


7.6.0 


11-2006 


CP-34 


CP-060670 


1053 


4 


PDP Context Activity Indication for Service Request (Service 
Type = Data) 


7.5.0 


7.6.0 


11-2006 


CP-34 


CP-060670 


1116 


- 


Deletion of LAI and PLMN from forbidden lists after LOCATION 
UPDATING ACCEPT 


7.5.0 


7.6.0 


11-2006 


CP-34 


CP-060670 


1117 


- 


Adding a Cipheirng Mode Setting indicator to MS Classmark3 


7.5.0 


7.6.0 


11-2006 


CP-34 


CP-060744 


1108 


5 


Initiation of Service Request to support MBMS broadcast 
services 


7.5.0 


7.6.0 


03-2007 


CP-35 


CP-070143 


1118 


1 


Addition of support for Network Bearer 


7.6.0 


7.7.0 


03-2007 


CP-35 


CP-070155 


1119 


2 


Criteria used by network to select a CKSN/KSI value 


7.6.0 


7.7.0 


03-2007 


CP-35 


CP-070155 


1120 


1 


Authentication parameter values stored in the UE separately for 


7.6.0 


7.7.0 
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the CS and the PS domain 






03-2007 


CP-35 


CP-070156 


1122 




Downlink Dual carrier multislot class indication 


7.6.0 


7.7.0 


03-2007 


CP-35 


CP-070155 


1124 


1 


Corrections to Network initiated PDP context modification 
procedure 


7.6.0 


7.7.0 


03-2007 


CP-35 


CP-070155 


1128 


2 


Introduction of Downlink Advanced Receiver Performance - 
phase II capability 


7.6.0 


7.7.0 


06-2007 


CP-3e 


CP-0703e9 


1136 


1 


Signalling connection for MBMS reception in PTP mode 


7.7.0 


7.8.0 


06-2007 


CP-36 


CP-070386 


1142 


1 


Support of higher maximum bitrate and guaranteed bit rate in the 
QoSIE 


7.7.0 


7.8.0 


06-2007 


CP-36 


CP-070387 


1144 


2 


MS indication of support of GAN PS Handover 


7.7.0 


7.8.0 


06-2007 


CP-3e 


CP-070387 


1138 


1 


Clarification for the Codec Bitmap 


7.7.0 


7.8.0 


06-2007 


CP-36 


CP-070387 


1137 


- 


Bearer capability IE for Emergency calls and EFR capable 
terminals 


7.7.0 


7.8.0 


06-2007 


CP-3e 


CP-070387 


1133 


- 


Indication of Flexible Timeslot Assignment support 


7.7.0 


7.8.0 


06-2007 


cp-3e 


CP-070392 


1134 


1 


Introduction of Latency Reduction capabilities 


7.7.0 


7.8.0 


09-2007 


CP-37 


CP-070582 


1149 


1 


Prohibition of implementing A5/2 in terminalsA5/2 in termi 


7.8.0 


7.9.0 


09-2007 


CP-37 


CP-070591 


1148 


2 


Stage 3 alignment of Network Bearer control when BCM is 
MS/NW 


7.8.0 


7.9.0 


09-2007 


CP-37 


CP-070598 


1147 


1 


Extension of MS Classmark 3 IE length 


7.8.0 


7.9.0 


09-2007 


CP-37 


CP-070598 


1146 


1 


Clarification of UE behavior after receipt of ATTACH ACCEPT 
with Cause IE in response to combined ATTACH REQUEST 


7.8.0 


7.9.0 


09-2007 


CP-37 


CP-070598 


1145 


2 


Addition of Positioning Capability Transfer over RRLP 


7.8.0 


7.9.0 


12-2007 


CP-38 


CP-070789 


1158 


1 


Correction to MBMS context deactivation 


7.9.0 


7.10.0 


12-2007 


CP-38 


CP-070789 


1156 


2 


Correction to the TMGI 


7.9.0 


7.10.0 


12-2007 


CP-38 


CP-070804 


1153 


1 


Introduction of EGPRS2 capabilities 


7.9.0 


7.10.0 


12-2007 


CP-38 


CP-070815 


1152 


1 


Correction of misleading comments in the MS Classmark 3 and 
MS Radio Access Capability 


7.10.0 


8.0.0 


03-2008 


CP-39 


CP-080034 


1168 




TMGI misalignment between figure and table text 


8.0.0 


8.1.0 


03-2008 


CP-39 


CP-080136 


1165 




Handling of NAS-layer cause value when in GAN 


8.0.0 


8.1.0 


06-2008 


CP-40 


CP-080339 


1177 




Correction of description of security handling during inter-system 
handover 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-080347 


1174 


1 


Correction of handling unkown or unforseen transaction identifier 
in session management 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-080347 


1191 




Downlink Dual Carrier capability signalling for DTM 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-0803ei 


1186 


2 


RAU attempt counter and PLMN-SEARCH substate 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-080361 


1172 


1 


Add cause value #1 12(APN restriction value incompatible with 
active PDP context) to the PDP context deactivation initiated by 
the network 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-0803ei 


1184 




Correction of MM states in the tables in the timer section 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-0803ei 


1178 




Correction to CS messages and tables 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-0803e2 


1193 


2 


Changes to TS24.008_AccessControl 


8.1.0 


8.2.0 


06-2008 


CP-40 


CP-080363 


1169 


3 


eCall identifier for differential routing 


8.1.0 


8.2.0 
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09-2008 


CP-41 


CP-080534 


1189 


4 


Avoidance of MM signalling for an eCall only terminal 


8.2.0 


8.3.0 


09-2008 


CP-41 


CP-080536 


1201 




Correction for IMSI detach procedure during dedicated mode 


8.2.0 


8.3.0 


09-2008 


CP-41 


CP-080519 


1203 




Latency Reduction support for non RTTI capable MSs 


8.2.0 


8.3.0 


09-2008 


CP-41 


CP-080519 


1205 




Stage 2 alignment related to Network bearer control 


8.2.0 


8.3.0 


09-2008 


CP-41 


CP-080529 


1207 




Clarification of access control for PPAC 


8.2.0 


8.3.0 


09-2008 


CP-41 


CP-080536 


1209 




TMSI reallocation in a location area where the UE isn't updated 


8.2.0 


8.3.0 


12-2008 


CP-42 


CP-080860 


1211 


2 


Changes to TS24.008_AccessControl 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080834 


1213 


1 


Multimedia CAT in the CS domain 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080867 


1214 


3 


Paging response for CS Fallback 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080837 


1216 




Indication of mobile station's E-UTRAN capability 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080838 


1218 


3 


CSG access control for HNB - defining new cause value and UE 
behavior 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080867 


1219 




CR on 24.008 -CSFB timer 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080867 


1226 




ISR for CSFB 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080866 


1227 


2 


NAS recovery specification in TS 24.008 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080866 


1228 




DRX Parameter support for SI mode 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080873 


1229 




Corrections for GPRS attach attempt counter and routing area 
update attempt counter 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080866 


1233 




P-TMSI signature handling due to SI mode to lu or A/Gb mode 
intersystem change 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080866 


1238 




Support of EPS NAS protocols 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080868 


1239 




Introduction of UE network capability IE 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080866 


1240 




PCO for IP address allocation options 


8.3.0 


8.4.0 


12-2008 


CP-42 


CP-080868 


1242 


2 


Indication of HSPA SRVCC capability 


8.3.0 


8.4.0 


12-2008 


CP-42 








Editorial cleanup by MCC 


8.3.0 


8.4.0 


03-2009 


CP-43 


CP-090125 


1243 


2 


Additon of E-UTRAN support in MS Network Capability 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090130 


1246 


1 


Security context handling on inter RAT mobility to 
GERAN/UTRAN 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090125 


1247 


2 


AMF coding for EPS 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090130 


1248 


2 


SM and GMM sublayers coordination for supporting ISR 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090131 


1249 


2 


UE specific DRX Parameters handling in ATTACH/RAU 
procedure 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090159 


1253 


1 


Corrections for attach and RAU attempt counters 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090153 


1254 


1 


ISR local deactivation in the UE 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090159 


1255 


2 


Miscellaneous corrections for 24.008 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090156 


1257 


2 


CC and MM procedures for SRVCC 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090157 


1266 


1 


Invoking detach procedure through a CSG cell 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090157 


1267 


1 


Miscellaneous corrections 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090157 


1268 


1 


LU/RAU after manual selection of CSG cell 


8.4.0 


8.5.0 
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New 


03-2009 


CP-43 


CP-090159 


1270 


2 


Correction of initial conditions when UE registered for CS 
services in an area supporting NMO III moves to anotfier area 
with a different NMO 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090159 


1271 




Reference corrections 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090153 


1274 


1 


Additon of CS Fallback capability support in MS Network 
Capability 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090129 


1275 




NAS recovery on/off mechanism(3G) 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090125 


1277 


1 


Add new subclause which describes coordination between GMM 
and EMM 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090129 


1278 


1 


Proposal of UE EMM behavior on reception of error cause #9 
when UE executed RAU, combined RAU and Service Request 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090126 


1279 


2 


Clarifications for request type 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090131 


1280 


3 


Use of S-TMSI for the GPRS attach procedure 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090157 


1281 


2 


Update of CSG list in manual mode 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090123 


1283 


1 


Enhancement of inter RAT information container 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090128 


1284 


2 


Introducing E-UTRAN UE RAC Information 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090130 


1285 




Removal of EN for RAU reject (cause #1 2) 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090131 


1286 


2 


Update the PDN type with IPv4v6 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090125 


1290 


1 


Attach and routing area update abnormal cases: interaction with 
EMM 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090153 


1292 


1 


T3280 removal and corrections to procedures for CS fallback 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090157 


1295 


1 


Clarification on CSG related NAS behavior 


8.4.0 


8.5.0 


03-2009 


CP-43 


CP-090130 


1297 


1 


Proposal of UE EMM behavior on reception of error cause #10 
when UE executed RAU, combined RAU and Service Request 


8.4.0 


8.5.0 


06-2009 


CP-44 


CP-090410 


1298 




Combined RAU Reject(cause #12) 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090410 


1299 




Authentication failure parameter applicability 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090424 


1303 


1 


Subclause on PDP address allocation 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090421 


1304 


2 


Mobile Id for Paging Response 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090424 


1306 


1 


Clarification of TMSI reallocation procedure 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090410 


1308 


1 


Introduction of "reserved" code points for Request type IE 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090410 


1314 


1 


Correction for the main state change in the MS 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090421 


1317 




New trigger for location area updating procedure 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090421 


1318 




MM state when MS is under E-UTRAN coverage 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090421 


1319 




Emergency calls handling 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090424 


1321 


1 


Behaviour of GPRS MS operating in MS operation mode A or B 
on Service Reject with cause #7 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090410 


1323 


1 


Correction to mobile identity IE 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090426 


1326 


1 


Introduction of MS E-UTRA Capabilities 


8.5.0 


8.6.0 


06-2009 


CP-44 


CP-090410 


1327 




Replacing TRACKING AREA UPDATE REQUEST by ROUTING 
AREA UPDATE REQUEST 


8.5.0 


8.6.0 


09-2009 


CP-45 


CP-090652 


1307 


3 


Protocol Configuration Options support of PAP CHAP in EPS 


8.6.0 


8.7.0 
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New 


09-2009 


CP-45 


CP-090652 


1311 


7 


Providing the IVISISDN to the MS 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090733 


1320 


3 


Update of triggers for normal and combined routing area 
updating procedure 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090653 


1328 


1 


Security corrections to the RAU procedure 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090653 


1331 




Replacing "UE" by "MS" 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090677 


1332 


1 


Clarifications related to manual CSG selection 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090773 


1333 


3 


Correction of security key handling for SR VCC 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090677 


1337 




Correction to abnormal cases on the network side 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090652 


1339 


2 


Interaction between A/Gb or lu mode and SI mode 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090652 


1340 


1 


Local ISR deactivation upon last PDP context deactivation 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090674 


1341 


1 


Emergency calls when the MS is not registered to CS domain 
and camped on an E-UTRAN cell 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090679 


1343 


1 


Cause code to resolve race condition between UE-initiated and 
NW-initiated secondary PDP context activation 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090652 


1344 


2 


Inclusion of DNS server and P-CSCF IPv4 addresses in PCO 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090650 


1345 




Align the description of default bearer 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090668 


1348 


1 


eCall miscellaneous corrections 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090668 


1350 


1 


Amendments to mobility management procedures 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090651 


1357 


2 


Corrections to the figure of the GMM main states in the MS 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090653 


1358 


1 


Security for inter-system RAU from SI mode 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090651 


1360 




Corrections for description of cause #25 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090651 


1361 


1 


Correction on SM error cause #30 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090668 


1368 


1 


Determination of "eCall only" mode of operation 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090675 


1372 


1 


Parameters for SMS over SGs charging 


8.6.0 


8.7.0 


09-2009 


CP-45 


CP-090689 


1330 


1 


Introducing reject cause value for emergency service over GPPS 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090690 


1334 


3 


PDN Connection request type for emergency 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090682 


1336 


1 


Periodic routing area updating: editorial correction 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090689 


1346 


2 


GPRS Attach for emergency services 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090689 


1347 


1 


GPRS detach for emergency services 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090682 


1353 


2 


Enhanced Flexible Timeslot Assignment 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090682 


1354 


1 


Modification of Length Indicator Usage 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090690 


1359 


1 


Support indications for IMS Voice over PS session and 
emergency call 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090689 


1367 


2 


HLR detach request and PDP context deactivation by the SGSN 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090694 


1370 


1 


Update of allowed CSG list after successful manual selection of 
a CSG cell in a different PLMN 


8.7.0 


9.0.0 


09-2009 


CP-45 


CP-090692 


1371 


1 


Introduction of 128-bit ciphering key for A5/4 and GEA/4 


8.7.0 


9.0.0 


12-2009 


CP-46 


CP-090918 


1374 


1 


Correction for detach procedure 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1375 


2 


Add paging optimization procedure for CSG cell 


9.0.0 


9.1.0 
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New 


1 2-2009 


CP-46 


CP-090935 


1376 


3 


Clarification on the Closed mode CSG cell 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090922 


1377 


3 


UE voice capabilities/settings in IVIS network capability 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090922 


1378 


5 


Triggering conditions update for RAU 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090935 


1379 


3 


Operator CSG List 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090899 


1382 


1 


Handling of cause #1 5 in UE with S1 mode support 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1386 


1 


Detach on Timeout of Periodical Upate Timer 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090917 


1388 


1 


Clarification on setting SI value after SRVCC handover 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090915 


1396 


2 


LAU clarification for ISR and CSFB interworking 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090935 


1397 


5 


Processing the reject cause code #25 for the Operator CSG List 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090920 


1399 




PDP type IPv4v6 address length corrections 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1400 


2 


PDP Context activation and modification for emergency bearer 
services 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090922 


1401 


1 


Correction to conditions for GMM initiating service request 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090915 


1403 


1 


Missing establishment cause code mapping for CS fallback 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090922 


1410 




Introduction of Enhanced Multiplexing for Single TBF capability 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090899 


1413 




Key derivation in idle mode inter-RAT mobility 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090898 


1414 




Correction for Seperation bit of AMF 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1420 




GMM state machine on the UE side for emergency attach 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1421 


2 


GMM context handling for emergency attach 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1423 


2 


MS behaviour in case of EMC 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1424 


2 


Deactivate non-EMC bearers with CSG ID not in allowed CSG 
list 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1425 


1 


Handling of the forbidded list 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1426 


2 


Authentication procedure for EMC attach 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090922 


1427 


1 


Introduction of generic notification procedure 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1428 




Checks restrictions on attach for emergency bearer services 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090930 


1437 


1 


GPRS update status while UE is attached for emergency bearer 
services 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090939 


1438 




128-bit ciphering key for SRVCC 


9.0.0 


9.1.0 


1 2-2009 


CP-46 


CP-090939 


1439 




Correction to the definition of the UMTS security context and 
faulty message 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-091052 


1441 


2 


Alignment with TS23.401 caused by changing the term CSFB to 
"CSFB and SMS over SGs". 


9.0.0 


9.1.0 


12-2009 


CP-46 


CP-090919 


1409 


4 


Protecting the allowed CSG list 


9.0.0 


9.1.0 


03-2010 


CP-47 


CP-100144 


1392 


5 


Normal and Periodic Routing Area Update Procedure 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1418 


3 


Deactive ISR for UE attached for emergency bearer services 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100103 


1445 




Removal of T-GSM 900 capability 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1446 


1 


Disabling Integrity Checking for GMM, SM messages 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1447 




MS Initiated Detach Procedure 


9.1.0 


9.2.0 
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03-2010 


CP-47 


CP-100140 


1448 


1 


Clarification to l<ey derivation at SRVCC 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1450 


1 


Correction on CSG Id removal from Allowed CSG list 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100106 


1452 


2 


GPRS Kc handling at inter-system change from E-UTRAN to 
UTRAN/GERAN 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100129 


1454 


2 


Kc handling in SRVCC 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1455 


1 


Definition of attached for emergency bearer service 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1456 


1 


Selective camping capability correction 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1457 


2 


Defining Selective camping capability IE 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1458 


2 


RRC establishment cause for EMC of lu mode 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100126 


1460 


2 


Handling of Paging Response for CSFB 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1461 




Handling of CSFB mobile originating call 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1462 


1 


Handling authentication failure for EMC during RAU 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100126 


1467 


1 


Alignment term "CSFB and SMS over SGs" with TS23.401 (Part 
II) 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100106 


1469 


2 


Clarification on routing parameter for access stratum 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100135 


1470 


2 


Operator specific values for PCO 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100148 


1471 


1 


Use of Cause #25 when MS's subscription to CSG has expired - 
24.008 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1473 




Handling of inter RAT information container and E-UTRAN inter 
RAT information container 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100126 


1476 


1 


Removing triggers for rau after S1 mode to UTRAN lu mode 
intersystem change due to CS fallback without PS handover 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100126 


1478 


1 


Corrections on periodic routeing area update timer and 
GERAN/UTRAN Deactivate ISR timers in the UE 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1483 


1 


Using NAS-token in Attach Request 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1486 


2 


Emergency secondary PDP context activation 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100130 


1488 


1 


MM cause #25 for MM connection establishment 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1489 




Definition of non-emergency PDP context 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1490 




MS Substate PLMN Search 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1491 


2 


Attach for emergency bearer services to a network not 
supporting EM BS 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100134 


1493 


1 


Corrections to Network Feature Support IE. 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100126 


1498 


2 


Correction of CSFB capability indicator 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100144 


1499 


2 


Mobility aspects of Emergency attached UEs 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-100132 


1501 




Introduction of indication of support of GERAN to UTRAN 
priority-based cell reseiection - Option 1 


9.1.0 


9.2.0 


03-2010 


CP-47 


CP-1 00211 


1504 


2 


Correct terminating domain selection for IMS voice UEs 


9.1.0 


9.2.0 


06-2010 


CP-48 


CP-1 00371 


1509 


2 


Correction of LAU initiation during CSFB 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00354 


1510 


2 


Correction of LAU for CSFB in NMO 1 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00351 


1514 




Requested OoS in PDP context activation procedure 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00355 


1515 


1 


GPRS Kc128 handling at inter-system change from E-UTRAN to 


9.2.0 


9.3.0 
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UTRAN/GERAN 






06-2010 


CP-48 


CP-1 00360 


1517 


3 


GMM Authentication procedure for emergency services 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00354 


1518 


1 


Security context deletion 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00355 


1521 




IVIultiple TTI TBF capability 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00355 


1522 




Interpretation of Multislot Class Parameters for EFTA 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00354 


1525 


1 


Correction of conditions for RAU and ISR deactivation for T-ADS 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00360 


1536 


2 


Some corrections to tfie EMC procedure. 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00350 


1538 


2 


Clarification to network initiated detacfi procedure with cause 
#25 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00355 


1544 




Correction to MS Radio Access Capability Information Element 
encoding 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00349 


1547 




Derivation of the security context for CS domain because of 
SRVCC 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00354 


1548 




Correction to the applicability of security key for inter-sytem 
change from SI to lu 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00365 


1549 




Correction to the derivation of GPRS GSM Kc128 for inter-sytem 
change from SI to Gb 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00365 


1550 




Correction to 128-bit ciphering key handling 


9.2.0 


9.3.0 


06-2010 


CP-48 


CP-1 00360 


1551 


2 


Emergency attach reject from GMM in shared networks 


9.2.0 


9.3.0 


09-2010 


CP-49 


CP-1 00501 


1532 


2 


Corrections for Selective Camping 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00491 


1553 


4 


Correction to timer T3242 and T3243 values (eCall only MS) 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00506 


1554 


2 


Clarification to the T3302 timer value when a UE is emergency 
attached without security procedure. 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00506 


1555 


2 


Handling of Detach Procedure for IMSI services on a CSG cell 
which is no longer valid for the UE.and IMS EMG call is active. 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00506 


1560 


1 


Clarification to timer T331 8 and T3320 timer description in the 
EMC case. 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00485 


1581 


1 


Correction to the protocol configuration options lEI 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00501 


1585 


4 


Handling of location updating after CS fallback for mobile 
terminating calls 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00507 


1593 


2 


Introduction of MS CSG interworking capabilities 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00501 


1595 




Correction of implementation error of CR1372R1 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00501 


1598 


2 


Handling of collision of a Network Initiated Detach procdure with 
a Service Request procedure and a RAU procedure. 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00495 


1603 


1 


Location updating during CS fallback 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00506 


1604 


1 


Correction on storage of equivalent PLMNs list 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00520 


1613 




Corrections to UE mode of operation selection taking into 
account the UE's availability for voice calls in the IMS 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 00501 


1621 


2 


Alignment with 23.060 for SM cause value #52 "single address 
bearers only allowed" 


9.3.0 


9.4.0 


09-2010 


CP-49 


CP-1 0051 7 


1528 


2 


Local ISR deactivation in the UE when T3412 has expired 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 0051 7 


1540 


3 


Correcting ISR handling in UE 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 0051 4 


1562 


5 


PDN connection redirection in SIPTO scenario 


9.4.0 


10.0.0 
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09-2010 


CP-49 


CP-100514 


1563 


1 


Clarification on PDP Context re-activation 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-100517 


1564 


1 


Correction for value setting of the mobile reachable timer 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-100517 


1566 


2 


Correction for implicit detach timer 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1573 


1 


eCALL INACTIVE state and ATT flag 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00642 


1579 


2 


Maximum number of packet filters 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-100517 


1586 




LLC SAPI on PDP context activation for an MS capable of SI 
mode 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1587 


1 


MS behaviour when the network unexpectedly sets Selected 
Bearer Control Mode 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1594 




Introduction of Dynamic Timeslot Reduction capability 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-100517 


1599 


1 


TIN setting after location updating 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1600 


2 


Handling of cause #27 (missing or unknown APN) 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-100517 


1605 


1 


Correction on network initiated GPRS detach with cause #2 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1608 




Clarifying the updation of forbidden LA list 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1610 


1 


Clarification on READY timer behaviour 


9.4.0 


10.0.0 


09-2010 


CP-49 


CP-1 00520 


1617 




Correction to UTRAN Network sharing 


9.4.0 


10.0.0 


12-2010 


CP-50 


CP-1 00761 


1589 


4 


Correcting CJKV ideograph language ambiguity with the NITZ 
feature and UCS2 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00748 


1625 


1 


Add HNB name 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1628 


1 


Attach with IMSI 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1629 


7 


Extended Routing Area Update Timer 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1630 


4 


Rejection due to per APN congestion 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1631 


3 


Modified GMM Cause values for NIMTC 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1632 




Authentication not accepted by the network 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00751 


1634 




MS capability indication of VAMOS 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00742 


1635 




Correction of conditions for setting the CMST flag 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1638 




Deleting unnecessary trigger for initiating LAU procedure 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00742 


1648 




DCDL for EFTA 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1649 




Enhanced Multiplexing for a Single RLC Entity (EMSR) 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00747 


1653 




Handling of equivalent PLMN list when attached for emergency 
bearer services only 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1655 




NMOI indicator for MTC 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1657 




Correctin to the use of label "UMTS only" in various procedure. 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00736 


1660 




Correction of normal stop conditions for eCall and other timers 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1662 




Correction to the network inflated detach procedure with detach 
type "Re-attach required" 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00758 


1669 


3 


Cause value for terminating eMPS CS Fallback calls 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1670 


4 


RAU procedure when Low Priority indicator in MS changes 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1672 


2 


Explicit signalling of native vs mapped P-TMSI during RAU 


10.0.0 


10.1.0 
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12-2010 


CP-50 


CP-1 00760 


1673 


2 


Adding NAS signalling priority indication in Attach Request 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00754 


1674 




IFOM support PCO definition 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00742 


1678 


2 


Correcting conditions for inclusion of "voice domain preference 
and UE's usage setting" IE in Attach and RAU. 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1681 


3 


Clarifying the APN congestion control for EMC attached MS 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00747 


1685 


1 


Correction on GMM authentication failure for EMC services 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00760 


1686 


1 


SM procedures for low priority 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00761 


1690 




Correction of bearer capability length 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00753 


1641 


4 


PDN disconnection for LIRA 


10.0.0 


10.1.0 


12-2010 


CP-50 


CP-1 00767 


1644 


4 


Introduction of MOCN GERAN 


10.0.0 


10.1.0 


03-201 1 


CP-51 


CP-1 10193 


1683 


3 


Handling of pehodic RAU timer, mobile reachable timer and MM 
back-off timer 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1691 


3 


Clarification to the handling of SM cause value 27 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1692 


3 


Clarification to the handling of timer T3245 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1693 


5 


Handling of secondary PDP context activation procedure in case 
of APN congestion 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1696 


2 


Explicit Signalling Indication During Attach 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1701 


3 


Introduce cause value to reflect call rejection due to destinaton 
feature 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10183 


1704 


3 


Corrections to the PDP Context Deactivation 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1705 


2 


Low priority indication by the MS for the service request 
procedure 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1706 


2 


Integrity protection of periodic updates 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1710 


1 


Attach with IMSI Alignment of Terminology 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1711 


1 


Specific requirements Alignment of Terminology 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1712 


1 


NMO 1 behavior 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10183 


1713 


5 


Notify UE when a HNB provides access to a 
residential/enterprise IP network 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1715 




Clarification to SM cause value#31 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1717 


3 


Storage and handling of the NAS signalling low priority indicator 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1720 


2 


Correction on GPRS detach and service request collision 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1721 


1 


Correction on MS substate selection 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1722 


2 


Correction to reject cause value 48 name 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1723 


2 


Correction to Unsuccessful secondary PDP context activation 
procedure initiated by the MS 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1724 


2 


Completion of introduction of "Low priority" indication in 24.008 
CS messages 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1725 


4 


Adding NAS signalling priority indication in SM messages 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1726 


1 


Handling of Location Updating and CS Service Request after CS 
fallback for mobile originating calls 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1727 


3 


Correction of the handling of the P-TMSI type IE 


10.1.0 


10.2.0 
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03-201 1 


CP-51 


CP-1 10195 


1728 


1 


Maximum Transmission Unit in Protocol configuration options 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10199 


1731 


1 


Allocation of Tl and assignment of CC state to alerting call for 
SRVCC 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1734 




GMM state after lower layers failure during TAU when TIN=GUTI 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1735 


3 


Stopping T331 1 when UE moves to PMM-CONNECTED mode 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10253 


1744 


1 


Changing "P-TMSI or IMSI" Information Element to "Mobile 
Identity" 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10171 


1747 




Correction to detection of CSG cell based on CSG ID 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1750 


4 


EAB support 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1753 


1 


Correction on PPAC description to include GPRS Attach 
procedure 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1756 


1 


Radio resource sublayer address TLLI handling 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10193 


1758 


2 


SM Backoff timer, Editor's note removal 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1761 


1 


MS initiated PDP Context Activation without PDP address 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10183 


1762 


3 


Restriction on the use of PDN connection for LIPA 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1763 




Editorial correction on Congestion level IE definition 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10253 


1765 


1 


RRC establishment cause for emergency PDP after normal 
GPRS attach 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10195 


1766 




Missing handling of undefined values for MBR and GBR by the 
MS 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10206 


1700 


4 


Mobility management congestion control and back-off timer 


10.1.0 


10.2.0 


03-201 1 


CP-51 


CP-1 10305 


1699 


3 


Device properties and RRC establishment cause = Delay 
tolerant -24.008 


10.1.0 


10.2.0 


06-201 1 


CP-52 


CP-1 10462 


1776 


1 


Corrections for overload behavior 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1779 


1 


Clearly specify conditions for UE actions at switch off for T3245, 
T3346 and T3396. 


10.2.0 


10.3.0 


06-2011 


CP-52 


CP-1 10462 


1780 


1 


Further clarification of PLMN reselection and handling of MM 
back-off timer 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10466 


1782 


1 


Modifications to Emergency Number List IE. 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10466 


1785 




Support of IPv6 Prefix Delegation 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10446 


1788 




Manipulation of CSG ID entries (in ACL and OCL) and the 
associated PLMN ID - 3G 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1792 




Specification of missing timer identities 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10476 


1793 




Correct conditions for including the connectivity type IE 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10476 


1794 


1 


Correct the trigger of the LIPA PDN disconnection 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1795 


1 


Reference to NAS configuration in USIM 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1796 


2 


Inter RAT Change 


10.2.0 


10.3.0 


06-2011 


CP-52 


CP-1 10462 


1798 


2 


Handling Network initiated procedure when backoff timer is 
running 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1799 


2 


Emergency attach during backoff 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1801 


1 


alignment about MM congestion control 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1808 


2 


Correction on MS behavior for SM cause #26 and #27 


10.2.0 


10.3.0 
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CR 
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06-201 1 


CP-52 


CP-1 10462 


1812 


1 


Clarification about APN based congestion control procedure 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1815 


2 


Correction of T3396 fiandiing for PDN connection reactivation 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10464 


1818 


2 


Clarification to condition of sending the Network feature durning 
periodic RAU procedure. 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1820 


1 


Per IVIS T3212 rather than T3212 multiplier 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1822 


2 


Attach with IMSI in CS domain at PLMN change for MTC devices 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10466 


1790 




Introduction of fast downlink frequency switching capability 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10462 


1791 


2 


Addition of MM backoff timer for CS 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10466 


1806 


1 


Preservation and network controlled QoS 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 10463 


1807 


1 


NAS signalling low priority indication for exception cases 


10.2.0 


10.3.0 


06-201 1 


CP-52 


CP-1 1051 5 


1827 


1 


Signalling of TIGHTER capabilities 


10.2.0 


10.3.0 


09-201 1 


CP-53 


CP-110680 


1770 


4 


Handling mobile reachable timer for back-off UE with emergency 
PDN connection 


10.3.0 


10.4.0 


09-2011 


CP-53 


CP-1 10680 


1821 


6 


Call forwarding, paging and long periodic timers 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1831 


1 


PDP Context Deactivation 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1832 


1 


Handling Timers T3246, T3346 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1833 


1 


Timer Table Update with EPS details 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1834 


2 


Handling NAS Low Priority Indication 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1835 


4 


Correction and clarification on the terminologies of NAS level 
congestion control 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-1 10682 


1847 


1 


Clarification of UE behavior when combined RAU is not accepted 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1850 


1 


Clarify the bit in the device properties 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-1 10683 


1854 


2 


Clarification on periodic routing area update 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1856 


1 


Scope of SM APN congestion control 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1859 


2 


Handling of paging for MT in CS when a MM back-off timer is 
running 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1861 


4 


Clarification of RAU triggered after paging 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1862 


1 


Establishing emergency services when T3246 or T3346 is 
running 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1882 


1 


Correction to cause #22 handling 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1908 


1 


Clarification on paging response for CSFB when a MM back-off 
timer is running 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1910 


1 


T3323 may not be started 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1911 




Removal of EMM cause 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-1 10665 


1914 


2 


Reject Cause handling while MS attaching for emergency bearer 
services 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-110680 


1917 


1 


Value of timer T3312 in the network 


10.3.0 


10.4.0 


09-201 1 


CP-53 


CP-1 10708 


1855 


5 


Correction to network-initiated detach procedure 


10.3.0 


10.4.0 


12-2011 


CP-54 


CP-1 10874 


1841 


3 


Coordination between SM and GMM for supporting ISR 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10851 


1892 


4 


PSAP Callback for eCalls 


10.4.0 


10.5.0 
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12-2011 


CP-54 


CP-1 10871 


1924 


4 


Setting Mobile Reachable timer, Implicit Detach Timer 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1929 




Timer granularity of GPRS timer 3 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10879 


1949 


1 


Clarifications for user connection attachment for SRVCC 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1951 


1 


Removal of undefined "forbidden PLMN for attach in S1 mode" 

list. 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1962 




Correction of MM back-off timer reference 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1964 


1 


Clarification on SM backoff while paged using IMSI 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1966 


2 


Correction of LAU trigger when EMM/GMM backoff 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10860 


1972 




START value storage on USIM at SRVCC handover 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10875 


1974 


1 


Introduction of Selective Ciphering on SACCH 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1978 


1 


Default Value for SM back-off timer 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10859 


1986 


5 


Old LAI in Attach/RAU procedure 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


1995 


2 


Release of the NAS signalling connection after completion of 
MS-initiated detach procedure 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


2000 


1 


LAU trigger when GMM backoff timer running 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


2017 


2 


Remove "CN congestion" indication and Introduce CN domain 
indicator 


10.4.0 


10.5.0 


12-2011 


CP-54 


CP-1 10871 


2019 


2 


Correction on the MO CSFB procedure during T3246 running 


10.4.0 


10.5.0 


03-2012 


CP-55 


CP-1 201 00 


2029 


1 


Removal of LLC Acknowledged mode 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 02 


2033 


2 


Re-attach for emergency bearer service 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 05 


2035 


1 


Modification of the location registration method in CS fallback 
procedure 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 20098 


2043 


1 


Correction of Combined RA/LA update triggers by CSFB UE 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 11 


2053 


2 


Release of NAS signalling connection with EWT 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 11 


2066 




Location Update when T3346 is running in NM01 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 11 


2072 


3 


Handling NAS signalling low priority indication 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 11 


2075 


3 


Correction to the handling of wait time from AS 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 06 


2078 


3 


Call Control state modelling for aSRVCC 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-120111 


2079 


1 


Correction for RAU triggering while T3346 and receiving of 
paging 


10.5.0 


10.6.0 


03-2012 


CP-55 


CP-1 201 11 


2081 


1 


Back-off timer handling in connected mode mobility 


10.5.0 


10.6.0 


03-2012 


CP-55 








Editorial fixes 


10.6.0 


10.6.1 


06-2012 


CP-56 


CP-1 20305 


1982 


6 


State verification to avoid state mismatch 


10.6.1 


10.7.0 


06-2012 


CP-5e 


CP-1 20293 


2098 


3 


Additional trigger to GPRS detach and abnormal case handling 


10.6.1 


10.7.0 


06-2012 


CP-56 


CP-1 20302 


2108 


4 


Trigger to Location Update procedure due to Manual PLMN 
selection when T3346 timer is running. 


10.6.1 


10.7.0 


06-2012 


CP-56 


CP-1 20296 


2124 


1 


Corrections to Alternative EFTA multislot class field 


10.6.1 


10.7.0 


06-2012 


CP-56 


CP-1 20302 


2134 


1 


Abnormal cases when Extended Wait Time is received 


10.6.1 


10.7.0 


06-2012 


CP-56 


CP-1 20302 


2156 


1 


Correction of high priority user 


10.6.1 


10.7.0 


06-2012 


CP-56 


CP-1 20302 


2171 


1 


Back-off timer handling in connected mode mobility/GERAN 


10.6.1 


10.7.0 
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New 


09-2012 


CP-57 


CP-1 20581 


2197 


2 


Clarify MS behaviour after deietion of forbidden lists 


10.7.0 


10.8.0 


09-2012 


CP-57 


CP-1 20581 


2205 


2 


Handling of MM procedure during combined RAU procedure 


10.7.0 


10.8.0 


09-2012 


CP-57 


CP-1 20572 


2210 


1 


IMSI detach triggered by last PDP context deactivation 


10.7.0 


10.8.0 


12-2012 


CP-58 


CP-1 20792 


2252 


1 


Tl flassignment in an originating call case 


10.8.0 


10.9.0 


12-2012 


CP-58 


CP-1 20792 


2274 


4 


Corrections to UE behaviour on originating aSRVCC call 


10.8.0 


10.9.0 


12-2012 


CP-58 


CP-1 20789 


2290 




Correction to session management handling for MBMS context 
activation 


10.8.0 


10.9.0 


03-2013 


CP-59 


CP-1 301 03 


2311 


2 


Corrections for attachment of user connection in "call delivered" 
state for SRVCC. 


10.9.0 


10.10.0 
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